LOW
Nova: insecure directory permissions in snapshots
Published Jan 23, 2014
3.3
LOWCVSS 2.0
EPSS 0.48%
Description
OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
Affected products
No data.
No data.
OpenStack 3 for RHEL 6
openstack-nova-0:2013.1.5-2.el6ost
Fixed · RHSA-2014:0366
OpenStack 4 for RHEL 6
openstack-nova-0:2013.2.2-2.el6ost
Fixed · RHSA-2014:0231
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-nova-0:2013.1.5-2.el6ost | Fixed | RHSA-2014:0366 |
| OpenStack 4 for RHEL 6 | openstack-nova-0:2013.2.2-2.el6ost | Fixed | RHSA-2014:0231 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://rhn.redhat.com/errata/RHSA-2014-0231.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/01/13/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-7048 Vendor Advisory
- https://bugs.launchpad.net/nova/+bug/1227027 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1040786 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4003 Advisory
- https://github.com/advisories/GHSA-grp5-h379-j75x Advisory
- https://github.com/openstack/nova/commit/75be5abd6b3fa0f7f27fe9c805f832cd41d44a5d
- https://github.com/openstack/nova/commit/8a34fc3d48c467aa196f65eed444ccdc7c02f19f
- https://github.com/openstack/nova/commit/9bd7fff8c0160057643cfc37c5e2b1cd3337d6aa
- https://nvd.nist.gov/vuln/detail/CVE-2013-7048
- https://www.cve.org/CVERecord?id=CVE-2013-7048
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2014-0231.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2014/01/13/2 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-7048 | Vendor Advisory | |
| https://bugs.launchpad.net/nova/+bug/1227027 | x_refsource_CONFIRMExploitPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1040786 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4003 | Advisory | |
| https://github.com/advisories/GHSA-grp5-h379-j75x | Advisory | |
| https://github.com/openstack/nova/commit/75be5abd6b3fa0f7f27fe9c805f832cd41d44a5d | ||
| https://github.com/openstack/nova/commit/8a34fc3d48c467aa196f65eed444ccdc7c02f19f | ||
| https://github.com/openstack/nova/commit/9bd7fff8c0160057643cfc37c5e2b1cd3337d6aa | ||
| https://nvd.nist.gov/vuln/detail/CVE-2013-7048 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-7048 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 23, 2014
Updated Aug 6, 2024
Reserved Dec 11, 2013
Link CVE-2013-7048
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4003 GHSA-GRP5-H379-J75X Assigner mitre
Published Jan 23, 2014
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2022-4003