5
CVSSv2

CVE-2013-6419

Published: 07/01/2014 Updated: 08/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack havana

Vendor Advisories

Synopsis Moderate: openstack-neutron security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated openstack-neutron packages that fix one security issue, severalbugs, and add various enhancements are now available for Red Hat EnterpriseLinux OpenStack Platform 40The Re ...
Debian Bug report logs - #732022 nova: CVE-2013-7048: Nova live snapshots use an insecure local directory Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Dec 2013 16:09:02 UTC Severity: important Tags: secu ...
Interaction error in OpenStack Nova and Neutron before Havana 201321 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handlerpy in Nova and (2) the neutron-m ...