PT-2017-6606 · Openstack · Openstack Compute

Vasyl Kaigorodov

·

Published

2017-08-09

·

Updated

2022-05-17

·

CVE-2015-2687

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Compute (nova) versions Icehouse through Juno, Havana
Description The issue allows local users to access VM volumes without proper permissions when live migration fails.
Recommendations For OpenStack Compute (nova) versions Icehouse through Juno, Havana, consider restricting access to VM volumes until a fix is available.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2687
GHSA-97FV-22HC-MRGJ
PYSEC-2017-145

Affected Products

Openstack Compute