Описание
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
Ссылки
- Vendor Advisory
- Patch
- Vendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:openstack:essex:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:2011.3:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.01758
Низкий
4.9 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
больше 14 лет назад
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
debian
больше 14 лет назад
Nova 2011.3 and Essex, when using the OpenStack API, allows remote aut ...
github
больше 4 лет назад
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
EPSS
Процентиль: 76%
0.01758
Низкий
4.9 Medium
CVSS2
Дефекты
CWE-264