CVE-2013-2256
published 2013-09-16CVE-2013-2256: OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote…
PriorityP429medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.83%
76.4th percentile
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.1.2-3 (bookworm) | nova 2013.1.2-3 (bookworm) |
| debian | nova | < nova 2013.1.3-1 (bookworm) | nova 2013.1.3-1 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.3 | 2013.1.3 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | >= 2013.1 < 2013.1.3 | 2013.1.3 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
ghsa6.0MEDIUM
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
ghsa·2022-05-17·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
OSV
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
osv·2022-05-17·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
OSV
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
osv·2022-05-14
CVE-2013-2256 [MEDIUM] OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
GHSA
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
ghsa·2022-05-14
CVE-2013-2256 [MEDIUM] OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
OSV
CVE-2013-2256: OpenStack Compute (Nova) before 2013
osv·2013-09-16·CVSS 6.0
CVE-2013-2256 [MEDIUM] CVE-2013-2256: OpenStack Compute (Nova) before 2013
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
OSV
CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property
osv·2013-09-16·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 6.0
CVE-2013-2256 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to crash if it received specially crafted network
requests.
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)
Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)
Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
aut
Red Hat
OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
vendor_redhat·2013-08-20·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Statement: Not vulnerable. Red Hat did not release the incomplete fix for CVE-2013-2256 in any products.
Package: openstack-nova (Red Hat OpenStack Platform 3) - Not affected
Package: openstack-nova (Red Hat OpenStack Platform 4) - Not affected
Red Hat
OpenStack: Nova private flavors resource limit circumvention
vendor_redhat·2013-08-06·CVSS 6.0
CVE-2013-2256 [MEDIUM] CWE-862 OpenStack: Nova private flavors resource limit circumvention
OpenStack: Nova private flavors resource limit circumvention
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-2256: nova - OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not pro...
vendor_debian·2013·CVSS 6.0
CVE-2013-2256 [MEDIUM] CVE-2013-2256: nova - OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not pro...
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Scope: local
bookworm: resolved (fixed in 2013.1.2-3)
bullseye: resolved (fixed in 2013.1.2-3)
forky: resolved (fixed in 2013.1.2-3)
sid: resolved (fixed in 2013.1.2-3)
trixie: resolved (fixed in 2013.1.2-3)
Debian
CVE-2013-4278: nova - The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Ha...
vendor_debian·2013·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278: nova - The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Ha...
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Scope: local
bookworm: resolved (fixed in 2013.1.3-1)
bullseye: resolved (fixed in 2013.1.3-1)
forky: resolved (fixed in 2013.1.3-1)
sid: resolved (fixed in 2013.1.3-1)
trixie: resolved (fixed in 2013.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
Vincent Danen ([email protected]) reports:
The previous fix was insufficient and did not fully fix the flaw, as noted here:
https://bugs.launchpad.net/ossa/+bug/1212179
The patch to fully correct this flaw is here (I believe it would be in addition to previously-mentioned patches):
https://github.com/openstack/nova/commit/4054cc4a22a1fea997dec76afb5646fd6c6ea6b9
Discussion:
Created openstack-nova tracking bugs for this issue:
Affects: fedora-all [bug 1000087]
Affects: epel-6 [bug 1000088]
---
Statement:
Not vulnerable. Red Hat did not release the incomplete fix for CVE-2013-2256 in any products.
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bo
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bod
Bugzilla
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [fedora-all]
bugzilla·2013-08-08·CVSS 6.0
CVE-2013-2256 [MEDIUM] CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [fedora-all]
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
P
Bugzilla
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [epel-6]
bugzilla·2013-08-08·CVSS 6.0
CVE-2013-2256 [MEDIUM] CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [epel-6]
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-2256 OpenStack: Nova private flavors resource limit circumvention
bugzilla·2013-08-05·CVSS 6.0
CVE-2013-2256 [MEDIUM] CVE-2013-2256 OpenStack: Nova private flavors resource limit circumvention
CVE-2013-2256 OpenStack: Nova private flavors resource limit circumvention
Jeremey Stanley ([email protected]) reports:
Title: Resource limit circumvention in Nova private flavors
Reporter: hzrandd (NetEase)
Products: Nova
Affects: All versions
hzrandd from NetEase reported a resource limit circumvention
vulnerability in Nova's handling of private flavors. Any tenant is
able to show and boot any other tenant's private flavors by guessing
a flavor ID. This not only exposes the flavor's name, memory and
disk size, swap allocation, VCPU count and similar flavor
properties, but potentially allows circumvention of any resource
limits enforced through the os-flavor-access:is_public property.
Havana (development branch) fix:
https://review.openstack.org/34963
Grizzly fix:
https://review.o
2013-09-16
Published