Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0259

Опубликовано: 10 мар. 2015
Источник: redhat
CVSS2: 4.9

Описание

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

It was discovered that the OpenStack Compute (nova) console websocket did not correctly verify the origin header. An attacker could use this flaw to conduct a cross-site websocket hijack attack. Note that only Compute setups with VNC or SPICE enabled were affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-novaWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-novaFixedRHSA-2015:084416.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-novaFixedRHSA-2015:084316.04.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-novaFixedRHSA-2015:079007.04.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1190112openstack-nova: console Cross-Site WebSocket hijacking

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

nvd
почти 11 лет назад

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

debian
почти 11 лет назад

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, an ...

suse-cvrf
больше 10 лет назад

Security update for Cloud Compute 12

github
больше 3 лет назад

OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity

4.9 Medium

CVSS2