OpenStack是美国美国国家航空航天局(NASA)的一个云平台管理项目。 OpenStack 存在安全漏洞,该漏洞源于允许未经身份验证的远程攻击者在发现 undercloud 的 IP 地址后检查敏感数据,攻击者利用该漏洞可以获取私人信息,包括管理员访问凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenStack Platform 13.0 - ELS | 0:8.4.9-13.el7ost ~ * |
cpe:/a:redhat:openstack:13::el7
|
|
| Red Hat | Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | 0:8.4.9-13.el7ost ~ * |
cpe:/a:redhat:openstack:13::el7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-4853 | 8.1 HIGH | Quarkus: http security policy bypass |
| CVE-2022-3916 | 6.8 MEDIUM | Keycloak: session takeover with oidc offline refreshtokens |
| CVE-2022-1438 | 6.4 MEDIUM | Keycloak: xss on impersonation under specific circumstances |
No comments yet