7.1
CVSSv2

CVE-2013-7130

Published: 06/02/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows malicious users to obtain snapshot root disk contents of other users via ephemeral storage.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack compute 2012.2

openstack compute 2013.1.1

openstack compute 2013.1.2

openstack havana -

openstack compute 2013.1

openstack grizzly -

openstack icehouse -

openstack compute 2013.1.3

Vendor Advisories

Several security issues were fixed in OpenStack Nova ...
Debian Bug report logs - #736465 nova: CVE-2013-7130: Live migration can leak root disk into ephemeral storage Package: nova; Maintainer for nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 23 Jan 2014 22:27:01 UTC Severity: important Tags: ...
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage ...