Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3038▲ 464 respecto a la semana anterior
Críticas / altas1416▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)387▲ 170 respecto a la semana anterior
–

609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.1)0.32%—Openstack Glance StoreAI25/9/202630/9/2026
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
Pendiente de análisisMedia (6.5)0.30%—Openstack GlanceAI25/9/202630/9/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH…
Pendiente de análisisCrítica (9.2)0.27%—Openstack ZaqarAI24/9/202626/9/2026
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read,…
Pendiente de análisisMedia (5.3)0.24%—Openstack SwiftAI24/9/202624/9/2026
In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a…
Pendiente de análisisCrítica (9.4)0.53%—Openstack OctaviaAI21/9/202624/9/2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed…
Pendiente de análisisCrítica (9.4)0.53%—Openstack OctaviaAI21/9/202622/9/2026
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, and thus newlines passed structural checks, but Octavia stored and wrote the raw…
Pendiente de análisisAlta (7.2)0.41%—Openstack BlazarAI18/9/202622/9/2026
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it…
Pendiente de análisisAlta (7.1)0.37%—Openstack BlazarAI18/9/202622/9/2026
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs,…
Pendiente de análisisMedia (5.3)0.23%—Openstack IronicAI17/9/202618/9/2026
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
Pendiente de análisisAlta (7)0.45%—Openstack GlanceAI14/9/202622/9/2026
In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location…
Pendiente de análisisMedia (6.3)0.33%—Openstack IronicAI11/9/202622/9/2026
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Pendiente de análisisAlta (7.6)0.55%—Openstack KeystoneAI11/9/202622/9/2026
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can…
Pendiente de análisisAlta (7.1)0.38%—Openstack KeystoneAI27/8/20269/9/2026
In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing…
Pendiente de análisisAlta (7.6)0.60%—Openstack KeystoneAI25/8/20263/9/2026
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented…
Pendiente de análisisAlta (7.6)0.57%—Openstack KeystoneAI25/8/20269/9/2026
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that…
Pendiente de análisisBaja (2.2)0.29%—Openstack GlanceAI20/8/20269/9/2026
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been…
Pendiente de análisisAlta (8.4)0.54%—Openstack AodhAIOpenstack WatcherAI19/8/20269/9/2026
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch…
Pendiente de análisisMedia (6.3)0.30%—Openstack IronicAI14/8/20261/9/2026
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
Pendiente de análisisMedia (4.3)0.33%—Openstack OctaviaAI14/8/20269/9/2026
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Pendiente de análisisMedia (6.8)0.52%—Openstack DesignateAI12/8/20269/9/2026
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path.…
Pendiente de análisisCrítica (9.6)0.53%—Openstack DesignateAI12/8/20269/9/2026
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that…
Pendiente de análisisMedia (5)0.28%—Openstack IronicAI5/8/20269/9/2026
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
Pendiente de análisisMedia (6)0.44%—Openstack SwiftAI5/8/20269/9/2026
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from…
Pendiente de análisisMedia (6)0.41%—Openstack SwiftAI5/8/20269/9/2026
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary…
Pendiente de análisisAlta (8.7)0.84%—Openstack SwiftAI5/8/20269/9/2026
In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy…