Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2030

Опубликовано: 09 мая 2013
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 2.1openstack-novaAffected
RHOS Essex Releaseopenstack-novaWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=958285nova: insecure directory creation for signing

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

nvd
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

debian
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, a ...

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Nova uses insecure keystone middleware tmpdir by default

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2