OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
BID:65276
Info
OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 65276 |
| Class: | Design Error |
| CVE: |
CVE-2013-6491 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2014 12:00AM |
| Updated: | Aug 21 2014 12:14AM |
| Credit: | Red Hat Security Response Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
OpenStack Compute (Nova) is prone to security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and disclose sensitive information. Successful exploits may lead to other attacks.
OpenStack Compute (Nova) is prone to security-bypass vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and disclose sensitive information. Successful exploits may lead to other attacks.
Exploit / POC
OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Compute (Nova) SSL Certificate Validation Security Bypass Vulnerability
References:
References: