CVE-2012-3360
published 2012-07-22CVE-2012-3360: Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
3.00%
85.9th percentile
Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1.1-2 (bookworm) | nova 2012.1.1-2 (bookworm) |
| openstack | essex | — | — |
| openstack | folsom | — | — |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Nova Directory traversal vulnerability
ghsa·2022-05-17
CVE-2012-3360 [MEDIUM] CWE-22 OpenStack Nova Directory traversal vulnerability
OpenStack Nova Directory traversal vulnerability
Directory traversal vulnerability in `virt/disk/api.py` in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
OSV
OpenStack Nova Directory traversal vulnerability
osv·2022-05-17
CVE-2012-3360 [MEDIUM] OpenStack Nova Directory traversal vulnerability
OpenStack Nova Directory traversal vulnerability
Directory traversal vulnerability in `virt/disk/api.py` in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
OSV
CVE-2012-3360: Directory traversal vulnerability in virt/disk/api
osv·2012-07-22·CVSS 5.5
CVE-2012-3360 [MEDIUM] CVE-2012-3360: Directory traversal vulnerability in virt/disk/api
Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2012-07-03·CVSS 5.5
CVE-2012-3360 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to overwrite or corrupt arbitrary files in the
compute host file system.
Matthias Weckbecker discovered that, when using the OpenStack API to
setup libvirt-based hypervisors, an authenticated user could inject
files in arbitrary locations on the file system of the host running
Nova. A remote attacker could use this to gain root privileges. This
issue only affects Ubuntu 12.04 LTS. (CVE-2012-3360)
Pádraig Brady discovered that an authenticated user could corrupt
arbitrary files of the host running Nova. A remote attacker could
use this to cause a denial of service or possibly gain privileges.
(CVE-2012-3361)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-3360: nova - Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova...
vendor_debian·2012·CVSS 5.5
CVE-2012-3360 [MEDIUM] CVE-2012-3360: nova - Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova...
Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
Scope: local
bookworm: resolved (fixed in 2012.1.1-2)
bullseye: resolved (fixed in 2012.1.1-2)
forky: resolved (fixed in 2012.1.1-2)
sid: resolved (fixed in 2012.1.1-2)
trixie: resolved (fixed in 2012.1.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [epel-6]
bugzilla·2012-07-28·CVSS 5.5
CVE-2012-3360 [MEDIUM] CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [epel-6]
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=s
Bugzilla
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [fedora-all]
bugzilla·2012-07-28·CVSS 5.5
CVE-2012-3360 [MEDIUM] CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [fedora-all]
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?typ
Bugzilla
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images
bugzilla·2012-06-28·CVSS 5.5
CVE-2012-3360 [MEDIUM] CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images
CVE-2012-3360 OpenStack-Nova: compute nodes file injection in disk images
Thierry Carrez reports:
Title: Arbitrary file injection/corruption through directory
traversal issues Impact: Critical Reporter: Matthias Weckbecker
(SUSE Security team)
Description: Matthias Weckbecker from SUSE Security team reported a
vulnerability in Nova compute nodes handling of file injection in
disk images. By requesting files to be injected in malicious paths,
a remote authenticated user could inject files in arbitrary
locations on the host file system, potentially resulting in full
compromise of the compute node. Only Essex and later setups running
the OpenStack API over libvirt-based hypervisors are affected.
Discussion:
This is public now www.openwall.com/lists/oss-security/2012/07/03/2 filing tracke
http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083984.htmlhttp://secunia.com/advisories/49763http://secunia.com/advisories/49802http://www.securityfocus.com/bid/54277http://www.ubuntu.com/usn/USN-1497-1https://bugs.launchpad.net/nova/+bug/1015531https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9https://lists.launchpad.net/openstack/msg14089.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-July/083984.htmlhttp://secunia.com/advisories/49763http://secunia.com/advisories/49802http://www.securityfocus.com/bid/54277http://www.ubuntu.com/usn/USN-1497-1https://bugs.launchpad.net/nova/+bug/1015531https://github.com/openstack/nova/commit/2427d4a99bed35baefd8f17ba422cb7aae8dcca7https://github.com/openstack/nova/commit/b0feaffdb2b1c51182b8dce41b367f3449af5dd9https://lists.launchpad.net/openstack/msg14089.html
2012-07-22
Published