CVE Vulnerabilities

CVE-2013-2030

Published: Dec 27, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Affected Software

NameVendorStart VersionEnd Version
ComputeOpenstack2013.1 (including)2013.1 (including)
ComputeOpenstack2013.1.1 (including)2013.1.1 (including)
ComputeOpenstack2013.1.2 (including)2013.1.2 (including)
ComputeOpenstack2013.1.3 (including)2013.1.3 (including)
FolsomOpenstack- (including)- (including)
GrizzlyOpenstack2013.1 (including)2013.1 (including)
HavanaOpenstackhavana-1 (including)havana-1 (including)
HavanaOpenstackhavana-2 (including)havana-2 (including)
HavanaOpenstackhavana-3 (including)havana-3 (including)
NovaUbuntudevel*
NovaUbuntuquantal*
NovaUbunturaring*
NovaUbuntuupstream*

References