Openstack Platform
Vendor:
First CVE: Nov 27, 2017 · Active for 8 years
39
Total CVEs
More Total CVEs than 97% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Openstack Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 27, 2017
8 years ago
Most Recent CVE
Nov 7, 2024
624 days ago
CVE Severity & Scoring
Openstack Platform39 CVEs
51%
41%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (23.1%)
Network30 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (82.1%)
High7 (17.9%)
Unknown0 (0.0%)
User Interaction
None37 (94.9%)
Unknown0 (0.0%)
Required2 (5.1%)
Privileges Required
Low16 (41.0%)
High5 (12.8%)
None18 (46.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2021-3654MEDIUM A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. | Mar 2, 2022 | 6.1 | 46 | NO | YES |
CVE-2020-10731CRITICAL A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation | Jul 31, 2020 | 9.9 | 31 | NO | NO |
CVE-2022-23451HIGH An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from a | Sep 6, 2022 | 8.1 | 27 | NO | NO |
CVE-2017-15114HIGH When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no addi | Nov 27, 2017 | 8.1 | 27 | NO | NO |
CVE-2024-8007HIGH A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromis | Aug 21, 2024 | 8.1 | 25 | NO | NO |
CVE-2022-3596HIGH An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the underc | Sep 20, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-1668HIGH A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue resul | Apr 10, 2023 | 8.2 | 25 | NO | NO |
CVE-2021-20270HIGH An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated | Mar 23, 2021 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.1% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Openstack Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 17.1 | 5 | 6.9 | 38.9% | 1 | 2 |
| 17.0 | 5 | 5.7 | 0.6% | 0 | 0 |
| 16.2 | 16 | 6.6 | 14.4% | 1 | 3 |
| 16.1 | 18 | 6.6 | 12.9% | 1 | 3 |
| 16.0 | 2 | 7.9 | 1.3% | 0 | 0 |
| 15.0 | 2 | 8.2 | 0.6% | 0 | 0 |
| 14.0 | 1 | 6.5 | 0.3% | 0 | 0 |
| 13.0 | 21 | 6.4 | 0.9% | 0 | 0 |
| 12.0 | 1 | 8.1 | 1.5% | 0 | 0 |
| 10.0 | 7 | 6.5 | 0.9% | 0 | 0 |