CVE-2013-0326
published 2019-12-05CVE-2013-0326: OpenStack nova base images permissions are world readable
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.36%
28.5th percentile
OpenStack nova base images permissions are world readable
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nova | — | — |
| openstack-nova | openstack-nova | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h75p-45hp-3m75: OpenStack nova base images permissions are world readable
ghsa_unreviewed·2022-05-05
CVE-2013-0326 [LOW] GHSA-h75p-45hp-3m75: OpenStack nova base images permissions are world readable
OpenStack nova base images permissions are world readable
OSV
CVE-2013-0326: OpenStack nova base images permissions are world readable
osv·2019-12-05·CVSS 5.5
CVE-2013-0326 [MEDIUM] CVE-2013-0326: OpenStack nova base images permissions are world readable
OpenStack nova base images permissions are world readable
Red Hat
nova: _base images permissions should not be world readable
vendor_redhat·2013-01-08·CVSS 5.5
CVE-2013-0326 [MEDIUM] CWE-732 nova: _base images permissions should not be world readable
nova: _base images permissions should not be world readable
OpenStack nova base images permissions are world readable
Package: openstack-nova (Red Hat OpenStack Platform 3) - Will not fix
Package: openstack-nova (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2013-0326: nova - OpenStack nova base images permissions are world readable
vendor_debian·2013·CVSS 5.5
CVE-2013-0326 [MEDIUM] CVE-2013-0326: nova - OpenStack nova base images permissions are world readable
OpenStack nova base images permissions are world readable
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
openstack-nova: CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable [openstack-rdo]
bugzilla·2013-07-02·CVSS 5.5
CVE-2013-0326 [MEDIUM] openstack-nova: CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable [openstack-rdo]
openstack-nova: CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable [openstack-rdo]
openstack-rdo tracking bug for openstack-nova: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
*** Bug 961135 has been marked as a duplicate of this bug. ***
---
This is already fixed in Icehouse-2 and will be included in Havana in the 2013.2.2 rebase.
---
CLOSING this is already fixed in Havana and IceHouse.
The fix is in in IceHouse
$ git branch
* (detached from origin/el6-havana)
el6
$ git log | grep 70b47d2a27a7b49c221ce096334ceaf542133d43 -A6
commit 70b47d2a27a7b49c221ce096334ceaf542133d43
Bugzilla
CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable
bugzilla·2013-02-21·CVSS 5.5
CVE-2013-0326 [MEDIUM] CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable
CVE-2013-0326 OpenStack nova: _base images permissions should not be world readable
Nir Magnezi of Red Hat reports:
Description of problem:
nova _base images permissions shouldn are world readable.
I'd expect more strict
Version-Release number of selected component (if applicable):
Folsom.
How reproducible:
100%
Steps to Reproduce:
1. Run few instances and check the files created at /var/lib/nova/instances/_base
2.
3.
Actual results:
nova _base images permissions are world readable.
-rw-r--r--. 1 nova nova 241M Dec 31 12:16 f7e6702d38be6ef3a5a66812d56615252a7f1e04.part
-rw-r--r--. 1 qemu qemu 9.8G Dec 31 12:17 f7e6702d38be6ef3a5a66812d56615252a7f1e04
-rw-r--r--. 1 qemu qemu 20G Dec 31 12:30 f7e6702d38be6ef3a5a66812d56615252a7f1e04_20
-rw-r--r--. 1 qemu qemu 40G Dec 31 12:37 f7e6702d
Bugzilla
(CVE-2013-0326) OpenStack nova: _base images permissions should not be world readable [openstack-2.1]
bugzilla·2013-01-08·CVSS 5.5
CVE-2013-0326 [MEDIUM] (CVE-2013-0326) OpenStack nova: _base images permissions should not be world readable [openstack-2.1]
(CVE-2013-0326) OpenStack nova: _base images permissions should not be world readable [openstack-2.1]
Description of problem:
nova _base images permissions shouldn are world readable.
I'd expect more strict
Version-Release number of selected component (if applicable):
Folsom.
How reproducible:
100%
Steps to Reproduce:
1. Run few instances and check the files created at /var/lib/nova/instances/_base
2.
3.
Actual results:
nova _base images permissions are world readable.
-rw-r--r--. 1 nova nova 241M Dec 31 12:16 f7e6702d38be6ef3a5a66812d56615252a7f1e04.part
-rw-r--r--. 1 qemu qemu 9.8G Dec 31 12:17 f7e6702d38be6ef3a5a66812d56615252a7f1e04
-rw-r--r--. 1 qemu qemu 20G Dec 31 12:30 f7e6702d38be6ef3a5a66812d56615252a7f1e04_20
-rw-r--r--. 1 qemu qemu 40G Dec 31 12:37 f7e6702d38be6ef3a5a6681
https://access.redhat.com/security/cve/cve-2013-0326https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0326https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-0326https://security-tracker.debian.org/tracker/CVE-2013-0326https://access.redhat.com/security/cve/cve-2013-0326https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0326https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-0326https://security-tracker.debian.org/tracker/CVE-2013-0326
2019-12-05
Published