Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w429-xc55-hc48

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

OpenStack Nova host data leak to vm instance in rescue mode

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 12.0.0a0

12.0.0a0

EPSS

Процентиль: 42%
0.00201
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

redhat
почти 12 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

nvd
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

debian
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 201 ...

EPSS

Процентиль: 42%
0.00201
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200