Описание
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | redhat-user-workloads/openstack-nova-compute | Not affected | ||
| Red Hat OpenStack Platform 13 (Queens) | redhat-user-workloads/openstack-nova-compute-ironic | Not affected | ||
| Red Hat OpenStack Platform 16.2 | redhat-user-workloads/openstack-nova-compute | Not affected | ||
| Red Hat OpenStack Platform 16.2 | redhat-user-workloads/openstack-nova-compute-ironic | Not affected | ||
| Red Hat OpenStack Platform 17.1 | redhat-user-workloads/openstack-nova-compute | Not affected | ||
| Red Hat OpenStack Platform 17.1 | redhat-user-workloads/openstack-nova-compute-ironic | Not affected | ||
| Red Hat OpenStack Platform 18.0 | redhat-user-workloads/openstack-nova-compute | Not affected | ||
| OpenStack Folsom for RHEL 6 | openstack-nova | Fixed | RHSA-2013:0709 | 04.04.2013 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) ...
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
EPSS
7.6 High
CVSS3