Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-3360

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 84.8%
CVSS Severity
CVSS v2 Score 5.5
References
Products affected by CVE-2012-3360
  • Openstack » Essex » Version: 2012.1
    cpe:2.3:a:openstack:essex:2012.1
  • Openstack » Folsom » Version: 2012.2
    cpe:2.3:a:openstack:folsom:2012.2


Contact Us

Shodan ® - All rights reserved