3.3
CVSSv2

CVE-2013-7048

Published: 23/01/2014 Updated: 16/11/2018
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and previous versions uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

Vendor Advisories

Debian Bug report logs - #732022 nova: CVE-2013-7048: Nova live snapshots use an insecure local directory Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Dec 2013 16:09:02 UTC Severity: important Tags: secu ...
OpenStack Compute (Nova) Grizzly 201314, Havana 201321, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots ...