PT-2013-5045 · Openstack · Openstack Compute

Cyberang3L

+1

·

Published

2013-11-05

·

Updated

2022-05-17

·

CVE-2013-4497

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions Folsom through Havana before 2013.2
Description The issue concerns the XenAPI backend in OpenStack Compute, where security groups are not properly applied in certain situations, allowing remote attackers to bypass intended restrictions. This occurs when resizing an image or during live migration.
Recommendations For OpenStack Compute (Nova) versions Folsom through Havana before 2013.2, update to version 2013.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4497
GHSA-27Q4-38QF-M25H
RHSA-2014:0366

Affected Products

Openstack Compute