PT-2014-3251 · Openstack · Openstack Compute

Daniel Berrange

·

Published

2014-01-23

·

Updated

2022-05-14

·

CVE-2013-7048

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions prior to Grizzly 2013.1.4 and Havana 2013.2.1
Description The issue allows local users to read and modify live snapshots due to world-writable and world-readable permissions for the temporary directory used to store them.
Recommendations For versions prior to Grizzly 2013.1.4 and Havana 2013.2.1, update to a version that includes the fix for this issue to prevent local users from reading and modifying live snapshots.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7048
GHSA-GRP5-H379-J75X
RHSA-2014:0231
RHSA-2014:0366

Affected Products

Openstack Compute