Vulnerabilities
Vulnerable Software
Openstack:  >> Nova  >> 2012.1  Security Vulnerabilities
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.
CVSS Score
4.9
EPSS Score
0.009
Published
2012-08-20
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
CVSS Score
3.5
EPSS Score
0.009
Published
2012-06-07


Contact Us

Shodan ® - All rights reserved