CVE Vulnerabilities

CVE-2013-0335

Insufficient Session Expiration

Published: Mar 22, 2013 | Modified: Jul 31, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

NameVendorStart VersionEnd Version
EssexOpenstack2012.1 (including)2012.1 (including)
FolsomOpenstack2012.2 (including)2012.2 (including)
GrizzlyOpenstack2012.2 (including)2012.2 (including)
OpenStack Folsom for RHEL 6RedHatopenstack-nova-0:2012.2.3-7.el6ost*
NovaUbuntuoneiric*
NovaUbuntuprecise*
NovaUbuntuquantal*
NovaUbuntuupstream*

Potential Mitigations

References