Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0134

Опубликовано: 25 мар. 2014
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-novaAffected
Red Hat OpenStack Platform 3openstack-novaWill not fix
OpenStack 4 for RHEL 6openstack-novaFixedRHSA-2014:057829.05.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1078002openstack-nova: Nova host data leak to vm instance in rescue mode

EPSS

Процентиль: 42%
0.00201
Низкий

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

nvd
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

debian
больше 11 лет назад

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 201 ...

CVSS3: 3.1
github
больше 3 лет назад

OpenStack Nova host data leak to vm instance in rescue mode

EPSS

Процентиль: 42%
0.00201
Низкий

3.5 Low

CVSS2