Openstack Platform

Vendor:

First CVE: Nov 27, 2017 · Active for 8 years

39
Total CVEs
More Total CVEs than 97% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Openstack Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 27, 2017
8 years ago
Most Recent CVE
Nov 7, 2024
624 days ago

CVE Severity & Scoring

Openstack Platform39 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local9 (23.1%)
Network30 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (82.1%)
High7 (17.9%)
Unknown0 (0.0%)
User Interaction
None37 (94.9%)
Unknown0 (0.0%)
Required2 (5.1%)
Privileges Required
Low16 (41.0%)
High5 (12.8%)
None18 (46.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
Mar 2, 20226.146NOYES
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation
Jul 31, 20209.931NONO
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from a
Sep 6, 20228.127NONO
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no addi
Nov 27, 20178.127NONO
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromis
Aug 21, 20248.125NONO
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the underc
Sep 20, 20237.525NONO
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue resul
Apr 10, 20238.225NONO
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated
Mar 23, 20217.525NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.1% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Openstack Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
17.156.938.9%12
17.055.70.6%00
16.2166.614.4%13
16.1186.612.9%13
16.027.91.3%00
15.028.20.6%00
14.016.50.3%00
13.0216.40.9%00
12.018.11.5%00
10.076.50.9%00