Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4497

Опубликовано: 05 нояб. 2013
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:havana:*:*:*:*:*:*:*:*
Версия до havana-3 (включая)
cpe:2.3:a:openstack:havana:havana-1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:havana:havana-2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00106
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 12 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

redhat
почти 13 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

debian
почти 12 лет назад

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Ha ...

github
около 3 лет назад

OpenStack Compute Nova Improper Access Control

EPSS

Процентиль: 29%
0.00106
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-264