PT-2013-3626 · Openstack · Openstack Compute

Hzrandd

·

Publicado

2013-09-16

·

Atualizado

2023-02-13

·

CVE-2013-2256

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions before 2013.1.3 OpenStack Compute (Nova) Havana versions before havana-2
Description The issue allows remote authenticated users to obtain sensitive information, such as flavor properties, boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id, due to the improper enforcement of the os-flavor-access:is public property.
Recommendations For OpenStack Compute (Nova) versions before 2013.1.3, update to version 2013.1.3 or later. For OpenStack Compute (Nova) Havana versions before havana-2, update to havana-2 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2256
GHSA-5MJ6-643F-2G85
RHSA-2013:1199

Produtos afetados

Openstack Compute