OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
BID:57613
Info
OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
| Bugtraq ID: | 57613 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0208 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2013 12:00AM |
| Updated: | Jan 31 2013 06:50PM |
| Credit: | Phil Day |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 amd64 |
| Not Vulnerable: | |
Discussion
OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
OpenStack Compute (Nova) is prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow attackers to bypass intended access controls and boot from arbitrary volumes.
OpenStack Compute (Nova) 2011.3, 2012.1 and 2012.2 are vulnerable.
OpenStack Compute (Nova) is prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow attackers to bypass intended access controls and boot from arbitrary volumes.
OpenStack Compute (Nova) 2011.3, 2012.1 and 2012.2 are vulnerable.
Exploit / POC
OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at:[email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at:[email protected].
Solution / Fix
OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenStack Compute (Nova) 'nova-volume' Security Bypass Vulnerability
References:
References:
- Vendor Homepage (OpenStack)