cbcvebase.
CVE-2012-0030
published 2012-01-13

CVE-2012-0030: Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI…

PriorityP425medium4.9CVSS 2.0
AVNACMAuSCNIPAP
EPSS
1.76%
75.5th percentile
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2012.1~rc1-1 (bookworm)nova 2012.1~rc1-1 (bookworm)
openstacknova
openstacknova>= 0 < 2012.1~rc1-12012.1~rc1-1
openstacknova>= 0 < 2012.1~rc1-12012.1~rc1-1
openstacknova>= 0 < 2012.1~rc1-12012.1~rc1-1
openstacknova>= 0 < 2012.1~rc1-12012.1~rc1-1

CVSS provenance

nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.