MEDIUM
openstack-nova: XenAPI security groups not kept through migrate or resize
Published Nov 5, 2013
6.4
MEDIUMCVSS 2.0
EPSS 1.82%
Description
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Affected products
No data.
No data.
OpenStack 3 for RHEL 6
openstack-nova-0:2013.1.5-2.el6ost
Fixed · RHSA-2014:0366
Red Hat OpenStack Platform 4
openstack-nova
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-nova-0:2013.1.5-2.el6ost | Fixed | RHSA-2014:0366 |
| Red Hat OpenStack Platform 4 | openstack-nova | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://www.openwall.com/lists/oss-security/2013/11/03/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2013/11/03/3 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2013-4497 Vendor Advisory
- https://bugs.launchpad.net/nova/+bug/1073306 x_refsource_CONFIRM
- https://bugs.launchpad.net/nova/+bug/1202266 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1026171 Issue Tracking
- https://github.com/advisories/GHSA-27q4-38qf-m25h Advisory
- https://github.com/openstack/nova/commit/01de658210fd65171bfbf5450c93673b5ce0bd9e
- https://github.com/openstack/nova/commit/5cced7a6dd32d231c606e25dbf762d199bf9cca7
- https://github.com/openstack/nova/commit/ba0d007fb78bd1182c3c0b808dbd7ccc84640e80
- https://github.com/openstack/nova/commit/df2ea2e3acdede21b40d47b7adbeac04213d031b
- https://launchpad.net/bugs/1073306
- https://launchpad.net/bugs/1202266
- https://nvd.nist.gov/vuln/detail/CVE-2013-4497
- https://www.cve.org/CVERecord?id=CVE-2013-4497
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 5, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4497
CISA Vulnrichment
GHSA-27Q4-38QF-M25H Updated n/a