PT-2014-3512 · Openstack+1 · Openstack Compute+1
Marc Heckmann
+1
·
Published
2014-04-15
·
Updated
2023-02-13
·
CVE-2014-0167
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions 2013.1 through 2013.2.3
OpenStack Compute (Nova) icehouse before icehouse-rc2
Description
The issue concerns the Nova EC2 API security group implementation, which fails to enforce Role-Based Access Control (RBAC) policies for certain methods, including
add rules, remove rules, and destroy, when non-default policies are used. This allows remote authenticated users to gain privileges via these API requests.Recommendations
For OpenStack Compute (Nova) versions 2013.1 through 2013.2.3, update to version 2013.2.4 or later.
For OpenStack Compute (Nova) icehouse before icehouse-rc2, update to icehouse-rc2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Compute
Ubuntu