Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-2256

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 76.1%
CVSS Severity
CVSS v2 Score 6.0
Products affected by CVE-2013-2256
  • Openstack » Nova » Version: 2013.1
    cpe:2.3:a:openstack:nova:2013.1
  • Openstack » Nova » Version: 2013.1.0
    cpe:2.3:a:openstack:nova:2013.1.0
  • Openstack » Nova » Version: 2013.1.1
    cpe:2.3:a:openstack:nova:2013.1.1
  • Openstack » Nova » Version: 2013.1.2
    cpe:2.3:a:openstack:nova:2013.1.2
  • Openstack » Nova » Version: 2013.2
    cpe:2.3:a:openstack:nova:2013.2


Contact Us

Shodan ® - All rights reserved