Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2030

Опубликовано: 27 дек. 2013
Источник: debian
EPSS Низкий

Описание

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novanot-affectedpackage

Примечания

  • http://lists.openstack.org/pipermail/openstack-announce/2013-May/000098.html

EPSS

Процентиль: 10%
0.00035
Низкий

Связанные уязвимости

ubuntu
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

redhat
больше 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

nvd
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Nova uses insecure keystone middleware tmpdir by default

EPSS

Процентиль: 10%
0.00035
Низкий