CVE-2012-2654
Summary
| CVE | CVE-2012-2654 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-21 15:55:12 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix up protocol case handling for security groups. · openstack/nova@ff06c7c · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654) : Mailing list archive : openstack team in Launchpad | af854a3a-2127-422b-91ae-364da2661108 | lists.launchpad.net | |
| Gerrit Code Review | af854a3a-2127-422b-91ae-364da2661108 | review.openstack.org | |
| Security Advisory SA49439 - Ubuntu update for nova - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fix up protocol case handling for security groups. · openstack/nova@9f9e9da · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Bug #985184 “Security groups fail to be set correctly if incorre...” : Bugs : OpenStack Compute (nova) | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| USN-1466-1: Nova vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Security Advisory SA46808 - OpenStack Compute (Nova) "Security Group" Security Bypass Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.