The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1935 | The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions. |
Github GHSA |
GHSA-27q4-38qf-m25h | OpenStack Compute Nova Improper Access Control |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:45:14.926Z
Reserved: 2013-06-12T00:00:00Z
Link: CVE-2013-4497
No data.
Status : Deferred
Published: 2013-11-05T20:55:29.633
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4497
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA