Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27q4-38qf-m25h

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Compute Nova Improper Access Control

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 12.0.0a0

12.0.0a0

EPSS

Процентиль: 28%
0.00094
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

redhat
почти 13 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

nvd
почти 12 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

debian
почти 12 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Ha ...

EPSS

Процентиль: 28%
0.00094
Низкий