6
CVSSv2

CVE-2014-0167

Published: 15/04/2014 Updated: 13/02/2023
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 prior to 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack compute 2013.1.1

openstack compute 2013.1.2

openstack compute 2013.1

openstack compute 2013.2.2

openstack compute 2013.2.3

openstack icehouse -

openstack compute 2013.2.1

openstack compute 2013.2

openstack compute 2013.1.3

Vendor Advisories

Several security issues were fixed in OpenStack Nova ...
Debian Bug report logs - #744051 CVE-2014-0167: RBAC policy not properly enforced in Nova EC2 API Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 9 Apr 2014 16:03:01 UTC Severity: important Tags: security, up ...
It was found that RBAC policies were not enforced in certain methods of the OpenStack Compute EC2 (Amazon Elastic Compute Cloud) API A remote attacker could use this flaw to escalate their privileges beyond the user group they were originally restricted to Note that only certain setups using non-default RBAC rules for OpenStack Compute were affec ...