Vulnerabilities
Vulnerable Software
Openstack:  >> Compute  >> 2013.2.3  Security Vulnerabilities
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
CVSS Score
4.7
EPSS Score
0.001
Published
2017-08-09
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.
CVSS Score
6.0
EPSS Score
0.004
Published
2014-04-15


Contact Us

Shodan ® - All rights reserved