Openstack Manila vulnerabilities
2 known vulnerabilities affecting openstack/manila.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-9543HIGHCVSS 8.3fixed in 7.4.1≥ 8.0.0, < 8.1.1+1 more2020-03-12
CVE-2020-9543 [HIGH] CWE-276 CVE-2020-9543: OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete
OpenStack Manila =8.0.0 =9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.
ghsanvdosv
CVE-2016-6519MEDIUMCVSS 5.4≤ 2.52017-04-21
CVE-2016-6519 [MEDIUM] CWE-79 CVE-2016-6519: Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 a
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.
nvd