Lucene search

K

Openstack-cinder Security Vulnerabilities

cve
cve

CVE-2020-10755

An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO....

6.5CVSS

6.2AI Score

0.001EPSS

2020-06-10 05:15 PM
43
cve
cve

CVE-2017-15139

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive.....

7.5CVSS

7.2AI Score

0.002EPSS

2018-08-27 05:29 PM
40
cve
cve

CVE-2014-7231

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the...

6.1AI Score

0.0004EPSS

2014-10-08 07:55 PM
21
cve
cve

CVE-2014-7230

The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the...

6.1AI Score

0.0004EPSS

2014-10-08 07:55 PM
22