Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0335

Опубликовано: 22 мар. 2013
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)redhat-user-workloads/openstack-nova-computeNot affected
Red Hat OpenStack Platform 13 (Queens)redhat-user-workloads/openstack-nova-compute-ironicNot affected
Red Hat OpenStack Platform 16.2redhat-user-workloads/openstack-nova-computeNot affected
Red Hat OpenStack Platform 16.2redhat-user-workloads/openstack-nova-compute-ironicNot affected
Red Hat OpenStack Platform 17.1redhat-user-workloads/openstack-nova-computeNot affected
Red Hat OpenStack Platform 17.1redhat-user-workloads/openstack-nova-compute-ironicNot affected
Red Hat OpenStack Platform 18.0redhat-user-workloads/openstack-nova-computeNot affected
OpenStack Folsom for RHEL 6openstack-novaFixedRHSA-2013:070904.04.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-613

EPSS

Процентиль: 80%
0.0212
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
ubuntu
больше 13 лет назад

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

CVSS3: 7.6
nvd
больше 13 лет назад

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

CVSS3: 7.6
debian
больше 13 лет назад

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) ...

CVSS3: 6.5
github
больше 4 лет назад

OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM

EPSS

Процентиль: 80%
0.0212
Низкий

7.6 High

CVSS3