CVE Vulnerabilities

CVE-2013-0335

Published: Mar 22, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Affected Software

Name Vendor Start Version End Version
Essex Openstack 2012.1 (including) 2012.1 (including)
Folsom Openstack 2012.2 (including) 2012.2 (including)
Grizzly Openstack 2012.2 (including) 2012.2 (including)
OpenStack Folsom for RHEL 6 RedHat openstack-nova-0:2012.2.3-7.el6ost *
Nova Ubuntu oneiric *
Nova Ubuntu precise *
Nova Ubuntu quantal *
Nova Ubuntu upstream *

References