PT-2013-2159 · Openstack · Openstack Compute

Published

2013-02-13

·

Updated

2017-08-29

·

CVE-2013-0208

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions Folsom through Essex
Description The boot-from-volume feature in OpenStack Compute (Nova) allows remote authenticated users to boot from other users' volumes via a volume id in the block device mapping parameter.
Recommendations For OpenStack Compute (Nova) versions Folsom through Essex, consider restricting access to the block device mapping parameter to prevent unauthorized booting from other users' volumes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0208
RHSA-2013:0208

Affected Products

Openstack Compute