CVE-2012-3361Incorrect Authorization in Nova

Severity
5.5MEDIUMNVD
EPSS
1.4%
top 19.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 17

Description

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 8.0 | Impact: 4.9

Affected Packages5 packages

PyPIopenstack/nova< 12.0.0a0
Debianopenstack/nova< 2012.1.1-2+3
NVDopenstack/essex2012.1
NVDopenstack/diablo2011.3
NVDopenstack/folsom2012.2

Patches

🔴Vulnerability Details

5
GHSA
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues2022-05-17
OSV
OpenStack Nova Arbitrary file injection/corruption through directory traversal issues2022-05-17
GHSA
Arbitrary file overwrite in OpenStack Nova2022-05-17
OSV
CVE-2012-3361: virt/disk/api2012-07-22
CVEList
CVE-2012-3361: virt/disk/api2012-07-22

📋Vendor Advisories

2
Ubuntu
Nova vulnerabilities2012-07-03
Debian
CVE-2012-3361: nova - virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), an...2012

💬Community

6
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [fedora-all]2012-08-08
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption (incomplete fix for CVE-2012-3361) [epel-6]2012-08-08
Bugzilla
CVE-2012-3447 OpenStack-Nova: compute nodes disk image file corruption, incomplete fix for CVE-2012-3361 (OSSA 2012-011)2012-08-01
Bugzilla
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [epel-6]2012-07-28
Bugzilla
CVE-2012-3361 OpenStack-Nova: compute nodes disk image file corruption [fedora-all]2012-07-28
CVE-2012-3361 — Incorrect Authorization in Nova | cvebase