PT-2013-5045 · Openstack · Openstack Compute
Cyberang3L
+1
·
Published
2013-11-05
·
Updated
2022-05-17
·
CVE-2013-4497
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Folsom through Havana before 2013.2
Description
The issue concerns the XenAPI backend in OpenStack Compute, where security groups are not properly applied in certain situations, allowing remote attackers to bypass intended restrictions. This occurs when resizing an image or during live migration.
Recommendations
For OpenStack Compute (Nova) versions Folsom through Havana before 2013.2, update to version 2013.2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Compute