Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2030

Опубликовано: 27 дек. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1

Описание

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

РелизСтатусПримечание
devel

ignored

hardy

DNE

lucid

DNE

oneiric

not-affected

precise

not-affected

quantal

ignored

raring

ignored

upstream

needed

Показывать по

Ссылки на источники

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

nvd
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

debian
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, a ...

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Nova uses insecure keystone middleware tmpdir by default

EPSS

Процентиль: 10%
0.00035
Низкий

2.1 Low

CVSS2