CVE-2012-2654
published 2012-06-21CVE-2012-2654: The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.63%
83.8th percentile
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1-6 (bookworm) | nova 2012.1-6 (bookworm) |
| openstack | compute | — | — |
| openstack | diablo | — | — |
| openstack | essex | — | — |
| openstack | nova | >= 0 < 2012.1-6 | 2012.1-6 |
| openstack | nova | >= 0 < 2012.1-6 | 2012.1-6 |
| openstack | nova | >= 0 < 2012.1-6 | 2012.1-6 |
| openstack | nova | >= 0 < 2012.1-6 | 2012.1-6 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-06-06
CVE-2012-2654 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be prevented from applying security group policy.
It was discovered that, when defining security groups in Nova using
the EC2 or OS APIs, specifying the network protocol (e.g. 'TCP') in
the incorrect case would cause the security group to not be applied
correctly. An attacker could use this to bypass Nova security group
restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2654: nova - The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (...
vendor_debian·2012·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654: nova - The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (...
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
Scope: local
bookworm: resolved (fixed in 2012.1-6)
bullseye: resolved (fixed in 2012.1-6)
forky: resolved (fixed in 2012.1-6)
sid: resolved (fixed in 2012.1-6)
trixie: resolved (fixed in 2012.1-6)
OSV
OpenStack Compute (Nova) Improper Input Validation
osv·2022-05-17
CVE-2012-2654 [MEDIUM] OpenStack Compute (Nova) Improper Input Validation
OpenStack Compute (Nova) Improper Input Validation
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
GHSA
OpenStack Compute (Nova) Improper Input Validation
ghsa·2022-05-17
CVE-2012-2654 [MEDIUM] CWE-20 OpenStack Compute (Nova) Improper Input Validation
OpenStack Compute (Nova) Improper Input Validation
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
OSV
CVE-2012-2654: The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012
osv·2012-06-21·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654: The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-17]
bugzilla·2012-06-06·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-17]
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=se
Bugzilla
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
bugzilla·2012-06-06·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=se
Bugzilla
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [epel-6]
bugzilla·2012-06-06·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [epel-6]
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=secur
Bugzilla
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly
bugzilla·2012-05-28·CVSS 4.3
CVE-2012-2654 [MEDIUM] CVE-2012-2654 OpenStack Nova security groups fail to be set correctly
CVE-2012-2654 OpenStack Nova security groups fail to be set correctly
From linux distros [email protected]
Title: Security groups fail to be set correctly
Impact: Medium
Reporter: HP Cloud Services [email protected]
Products: Nova
Affects: All versions
Description:
HP Cloud Services reported a vulnerability in Nova API handling. When a security group is created via the EC2 or OS API's that uses a protocol defined in the incorrect case i.e 'TCP' rather than 'tcp' it causes a later string comparison to fail. This leads to Security Groups not being set correctly. Once the Nova DB has been polluted with the incorrect case any subsequent modifications to the security group will also fail.
Proposed patch:
See attached diff. This proposed patch will be merged to Nova master and stabl
http://secunia.com/advisories/46808http://secunia.com/advisories/49439http://www.ubuntu.com/usn/USN-1466-1https://bugs.launchpad.net/nova/+bug/985184https://exchange.xforce.ibmcloud.com/vulnerabilities/76110https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654https://lists.launchpad.net/openstack/msg12883.htmlhttps://review.openstack.org/#/c/8239/http://secunia.com/advisories/46808http://secunia.com/advisories/49439http://www.ubuntu.com/usn/USN-1466-1https://bugs.launchpad.net/nova/+bug/985184https://exchange.xforce.ibmcloud.com/vulnerabilities/76110https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654https://lists.launchpad.net/openstack/msg12883.htmlhttps://review.openstack.org/#/c/8239/
2012-06-21
Published