Known vulnerabilities in openstack-nova (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:openstack-nova_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 7.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openstack-nova (Red Hat package) openstack-nova (Red Hat package) is affected by 6 known vulnerabilities: 2 medium, 4 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122995 - Allocation of Resources Without Limits or Throttling
CVE-2026-24708
CWE-770 Low
No
No
27.5.2-18.0.20260312122217.c1c6d67.el9ost 17.02.2026 SB2026021762
SB2026021847
SB2026022004
and 1 more
#VU96470 - Exposure of sensitive information to an unauthorized actor
CVE-2024-40767
CWE-200 Low
No
No
20.4.1-1.20221005193235.el8ost, 23.2.3-17.1.20231018123755.el8ost, 23.2.3-17.1.20231018130829.el9ost 23.08.2024 SB2024082303
SB2024082309
SB2024082310
and 2 more
#VU76039 - Permissions, Privileges, and Access Controls
CVE-2023-2088
CWE-264 Low
No
No
17.0.13-41.el7ost, 20.4.1-1.20221005193232.el8ost, 20.6.2-2.20230308185149.el8ost, 23.2.2-0.20221209190754.7074ac0.el9ost 11.05.2023 SB2023051132
SB2023051142
SB2023051143
and 7 more
#VU75530 - State Issues
CVE-2022-37394
CWE-371 Low
No
No
20.6.2-2.20230308185148.fc01371.el8ost 26.04.2023 SB2023042649
SB2023042650
#VU71714 - External Control of File Name or Path
CVE-2022-47951
CWE-73 Medium
No
No
17.0.13-40.el7ost, 20.4.1-1.20221005193231.1ee93b9.el8ost, 20.6.2-2.20221005185231.6786e96.el8ost, 23.2.2-0.20221209190753.7074ac0.el9ost 31.01.2023 SB2023013129
SB2023013130
SB2023013131
and 15 more
#VU55331 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-3654
CWE-601 Medium
No
No
20.4.1-1.20220112153422.1ee93b9.el8ost, 20.6.2-2.20220112164912.8906554.el8ost 27.07.2021 SB2021072712
SB2022032437
SB2022032440
and 2 more