CVE-2013-0335
published 2013-03-22CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances…
PriorityP431medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.15%
80.1th percentile
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | nova | < nova 2012.1.1-14 (bookworm) | nova 2012.1.1-14 (bookworm) |
| openstack | essex | — | — |
| openstack | folsom | — | — |
| openstack | grizzly | — | — |
| openstack | nova | >= 0 < 2012.1.1-14 | 2012.1.1-14 |
| openstack | nova | >= 0 < 2012.1.1-14 | 2012.1.1-14 |
| openstack | nova | >= 0 < 2012.1.1-14 | 2012.1.1-14 |
| openstack | nova | >= 0 < 2012.1.1-14 | 2012.1.1-14 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
ghsa·2022-05-05
CVE-2013-0335 [HIGH] CWE-863 OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OSV
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
osv·2022-05-05
CVE-2013-0335 [HIGH] OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OSV
CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
osv·2013-03-22·CVSS 6.0
CVE-2013-0335 [MEDIUM] CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Red Hat
CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
vendor_redhat·2013-03-22·CVSS 6.0
CVE-2013-0335 [MEDIUM] CWE-613 CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: redhat-user-workloads/openstack-nova-compute (Red Hat OpenStack Platform
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2013-03-20·CVSS 6.0
CVE-2013-0335 [MEDIUM] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: Two security issues were fixed in Nova.
Loganathan Parthipan discovered that Nova did not properly validate VNC
tokens after an instance was deleted. An authenticated attacker could
exploit this to access other virtual machines under certain circumstances.
This issue did not affect Ubuntu 11.10. (CVE-2013-0335)
Vish Ishaya discovered that Nova did not always enforce quotas on fixed
IPs. An authenticated attacker could exploit this to cause a denial of
service via resource consumption. Nova will now enforce a quota limit of
10 fixed IPs per instance, which is configurable via 'quota_fixed_ips'
in /etc/nova/nova.conf. (CVE-2013-1838)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-0335: nova - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows rem...
vendor_debian·2013·CVSS 6.0
CVE-2013-0335 [MEDIUM] CVE-2013-0335: nova - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows rem...
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Scope: local
bookworm: resolved (fixed in 2012.1.1-14)
bullseye: resolved (fixed in 2012.1.1-14)
forky: resolved (fixed in 2012.1.1-14)
sid: resolved (fixed in 2012.1.1-14)
trixie: resolved (fixed in 2012.1.1-14)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0709.htmlhttp://secunia.com/advisories/52337http://secunia.com/advisories/52728http://www.openwall.com/lists/oss-security/2013/02/26/7http://www.osvdb.org/90657http://www.ubuntu.com/usn/USN-1771-1https://bugs.launchpad.net/nova/+bug/1125378https://review.openstack.org/#/c/22086/https://review.openstack.org/#/c/22758https://review.openstack.org/#/c/22872/http://rhn.redhat.com/errata/RHSA-2013-0709.htmlhttp://secunia.com/advisories/52337http://secunia.com/advisories/52728http://www.openwall.com/lists/oss-security/2013/02/26/7http://www.osvdb.org/90657http://www.ubuntu.com/usn/USN-1771-1https://bugs.launchpad.net/nova/+bug/1125378https://review.openstack.org/#/c/22086/https://review.openstack.org/#/c/22758https://review.openstack.org/#/c/22872/
2013-03-22
Published