Vulnerabilities in The Openstack Project
2 resultsVexday analysis
O OpenStack Project apresenta apenas 2 CVEs catalogadas na base Vexday, nenhuma delas sob ataque ativo ou com severidade crítica. A fraqueza predominante é validação inadequada de entrada (CWE-20), e não há vulnerabilidades recentes nos últimos 90 dias, indicando baixa pressão de risco imediato para o fornecedor.
CVE-2018-14635MEDIUMWhen using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassiEPSS 2.5%CVE-2018-14636MEDIUMLive-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended EPSS 1.2%