CVE-2013-2256

Severity
6.0MEDIUM
EPSS
0.5%
top 35.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 17

Description

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages3 packages

NVDopenstack/nova2013.12013.1.3+1
PyPInova< 2013.1.3
Debiannova< 2013.1.2-3+3

Patches

🔴Vulnerability Details

5
GHSA
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors2022-05-17
OSV
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information2022-05-14
GHSA
OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive information2022-05-14
CVEList
CVE-2013-2256: OpenStack Compute (Nova) before 20132013-09-16
OSV
CVE-2013-2256: OpenStack Compute (Nova) before 20132013-09-16

📋Vendor Advisories

4
Ubuntu
Nova vulnerabilities2013-10-23
Red Hat
OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-22562013-08-20
Red Hat
OpenStack: Nova private flavors resource limit circumvention2013-08-06
Debian
CVE-2013-2256: nova - OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not pro...2013

💬Community

6
Bugzilla
CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-22562013-08-22
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]2013-08-22
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]2013-08-22
Bugzilla
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [fedora-all]2013-08-08
Bugzilla
CVE-2013-2256 openstack-nova: OpenStack: Nova private flavors resource limit circumvention [epel-6]2013-08-08