Vulnerabilidades em OpenStack
48 resultadosAnálise Vexday
OpenStack apresenta 43 vulnerabilidades registradas, com concentração crítica em autorização e controle de acesso (CWE-863); 30 foram publicadas nos últimos 90 dias, indicando risco em evolução constante. Embora nenhuma esteja sob ataque ativo documentado (KEV), o volume recente de divulgações e apenas 3 críticas sugerem um panorama de médio risco operacional que requer monitoramento contínuo de atualizações.
CVE-2026-55748MEDIUMOpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharaEPSS 0.2%CVE-2022-38060HIGHA privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sEPSS 0.2%CVE-2026-40214MEDIUMIn OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column EPSS 0.2%CVE-2026-40213HIGHOpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorEPSS 0.2%CVE-2025-44021LOWOpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via theEPSS 0.2%CVE-2026-71201MEDIUMIn OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned orEPSS 0.2%CVE-2026-50221MEDIUMIn OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-HosEPSS 0.1%CVE-2026-54422MEDIUMIn OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extracEPSS 0.1%