Vulnerabilities > Openstack > Compute > 2013.1.2

DATE CVE VULNERABILITY TITLE RISK
2014-02-06 CVE-2013-7130 Information Exposure vulnerability in Openstack products
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.
network
openstack CWE-200
7.1
2013-12-27 CVE-2013-2030 Permissions, Privileges, and Access Controls vulnerability in Openstack products
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
local
low complexity
openstack CWE-264
2.1
2013-10-29 CVE-2013-4185 Cryptographic Issues vulnerability in multiple products
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
network
low complexity
openstack redhat CWE-310
4.0