Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-2256

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.1%
CVSS Severity
CVSS v2 Score 6.0
Products affected by CVE-2013-2256
  • Openstack » Nova » Version: 2013.1
    cpe:2.3:a:openstack:nova:2013.1
  • Openstack » Nova » Version: 2013.1.0
    cpe:2.3:a:openstack:nova:2013.1.0
  • Openstack » Nova » Version: 2013.1.1
    cpe:2.3:a:openstack:nova:2013.1.1
  • Openstack » Nova » Version: 2013.1.2
    cpe:2.3:a:openstack:nova:2013.1.2
  • Openstack » Nova » Version: 2013.2
    cpe:2.3:a:openstack:nova:2013.2


Contact Us

Shodan ® - All rights reserved