CVE-2012-2654
Summary
| CVE | CVE-2012-2654 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-21 15:55:00 UTC |
| Updated | 2017-08-29 01:31:00 UTC |
| Description | The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Compute | 2012.2 | All | All | All |
| Application | Openstack | Compute | 2012.2 | All | All | All |
| Application | Openstack | Diablo | 2011.3 | All | All | All |
| Application | Openstack | Diablo | 2011.3 | All | All | All |
| Application | Openstack | Essex | 2012.1 | All | All | All |
| Application | Openstack | Essex | 2012.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-1466-1: Nova vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Fix up protocol case handling for security groups. · openstack/nova@ff06c7c · GitHub | CONFIRM | github.com | Exploit, Patch |
| Gerrit Code Review | CONFIRM | review.openstack.org | |
| Fix up protocol case handling for security groups. · openstack/nova@9f9e9da · GitHub | CONFIRM | github.com | Exploit, Patch |
| [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654) : Mailing list archive : openstack team in Launchpad | MLIST | lists.launchpad.net | |
| Security Advisory SA46808 - OpenStack Compute (Nova) "Security Group" Security Bypass Security Issue - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Security Advisory SA49439 - Ubuntu update for nova - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Bug #985184 “Security groups fail to be set correctly if incorre...” : Bugs : OpenStack Compute (nova) | CONFIRM | bugs.launchpad.net | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.