Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2030

Опубликовано: 27 дек. 2013
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:compute:2013.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.1.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.1.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*
cpe:2.3:a:openstack:grizzly:2013.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:havana:havana-1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:havana:havana-2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:havana:havana-3:*:*:*:*:*:*:*

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

redhat
больше 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

debian
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, a ...

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Nova uses insecure keystone middleware tmpdir by default

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2

Дефекты

CWE-264