4.9
CVSSv2

CVE-2012-0030

Published: 13/01/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack essex

openstack nova 2011.3

Vendor Advisories

Nova would allow unintended access to resources over the network ...