Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4278

Опубликовано: 20 авг. 2013
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.

Отчет

Not vulnerable. Red Hat did not release the incomplete fix for CVE-2013-2256 in any products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3openstack-novaNot affected
Red Hat OpenStack Platform 4openstack-novaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1000086OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256

EPSS

Процентиль: 72%
0.01497
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.

nvd
почти 13 лет назад

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.

debian
почти 13 лет назад

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizz ...

github
около 4 лет назад

OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors

EPSS

Процентиль: 72%
0.01497
Низкий

5.5 Medium

CVSS2