CVE Vulnerabilities

CVE-2013-2030

Published: Dec 27, 2013 | Modified: May 05, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Affected Software

Name Vendor Start Version End Version
Compute Openstack 2013.1 (including) 2013.1 (including)
Compute Openstack 2013.1.1 (including) 2013.1.1 (including)
Compute Openstack 2013.1.2 (including) 2013.1.2 (including)
Compute Openstack 2013.1.3 (including) 2013.1.3 (including)
Folsom Openstack - (including) - (including)
Grizzly Openstack 2013.1 (including) 2013.1 (including)
Havana Openstack havana-1 (including) havana-1 (including)
Havana Openstack havana-2 (including) havana-2 (including)
Havana Openstack havana-3 (including) havana-3 (including)
Nova Ubuntu devel *
Nova Ubuntu quantal *
Nova Ubuntu raring *
Nova Ubuntu upstream *

References