📦

manila

Vendor: openstack

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 20 Total Indexed
Avg. EPSS 1.21% Exploit Prob.
Latest CVE CVE-2020-9543 Mar 12

Security Vulnerability Index

Page 1 / 2
8.3 CVSS

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks.

EPSS: 1.15%
5.4 CVSS

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.

EPSS: 1.27%