virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essex | Openstack | 2012.1 | 2012.1 |
Folsom | Openstack | 2012.2 | 2012.2 |
Diablo | Openstack | 2011.3 | 2011.3 |