CVE-2013-0208
published 2013-02-13CVE-2013-0208: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users'…
PriorityP428medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.50%
83.0th percentile
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nova | < nova 2012.1.1-12 (bookworm) | nova 2012.1.1-12 (bookworm) |
| openstack | nova | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | nova | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | nova | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | nova | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: Boot from volume allows access to random volumes
vendor_redhat·2013-01-29·CVSS 6.5
CVE-2013-0208 [MEDIUM] openstack-nova: Boot from volume allows access to random volumes
openstack-nova: Boot from volume allows access to random volumes
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
Ubuntu
OpenStack Nova vulnerability
vendor_ubuntu·2013-01-29
CVE-2013-0208 OpenStack Nova vulnerability
Title: OpenStack Nova vulnerability
Summary: Nova volume could be made to expose volumes from other users.
Phil Day discovered that nova-volume did not validate access to volumes. An
authenticated attacker could exploit this to bypass intended access
controls and boot from arbitrary volumes.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-0208: nova - The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when ...
vendor_debian·2013·CVSS 6.5
CVE-2013-0208 [MEDIUM] CVE-2013-0208: nova - The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when ...
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
Scope: local
bookworm: resolved (fixed in 2012.1.1-12)
bullseye: resolved (fixed in 2012.1.1-12)
forky: resolved (fixed in 2012.1.1-12)
sid: resolved (fixed in 2012.1.1-12)
trixie: resolved (fixed in 2012.1.1-12)
GHSA
GHSA-rr64-vh7q-pgrf: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from oth
ghsa_unreviewed·2022-05-05
CVE-2013-0208 [MEDIUM] GHSA-rr64-vh7q-pgrf: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from oth
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
OSV
CVE-2013-0208: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from oth
osv·2013-02-13·CVSS 6.5
CVE-2013-0208 [MEDIUM] CVE-2013-0208: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from oth
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
No detection rules found.
No public exploits indexed.
http://osvdb.org/89661http://rhn.redhat.com/errata/RHSA-2013-0208.htmlhttp://secunia.com/advisories/51963http://secunia.com/advisories/51992http://www.openwall.com/lists/oss-security/2013/01/29/9http://www.securityfocus.com/bid/57613http://www.ubuntu.com/usn/USN-1709-1https://bugs.launchpad.net/nova/+bug/1069904https://bugzilla.redhat.com/show_bug.cgi?id=902629https://exchange.xforce.ibmcloud.com/vulnerabilities/81697https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193bhttps://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1adhttp://osvdb.org/89661http://rhn.redhat.com/errata/RHSA-2013-0208.htmlhttp://secunia.com/advisories/51963http://secunia.com/advisories/51992http://www.openwall.com/lists/oss-security/2013/01/29/9http://www.securityfocus.com/bid/57613http://www.ubuntu.com/usn/USN-1709-1https://bugs.launchpad.net/nova/+bug/1069904https://bugzilla.redhat.com/show_bug.cgi?id=902629https://exchange.xforce.ibmcloud.com/vulnerabilities/81697https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193bhttps://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad
2013-02-13
Published