CVE-2013-4278
published 2013-09-16CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which…
PriorityP420low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.50%
71.4th percentile
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.1.3-1 (bookworm) | nova 2013.1.3-1 (bookworm) |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
ghsa6.0MEDIUM
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 6.0
CVE-2013-2256 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to crash if it received specially crafted network
requests.
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)
Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)
Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
aut
Red Hat
OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
vendor_redhat·2013-08-20·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Statement: Not vulnerable. Red Hat did not release the incomplete fix for CVE-2013-2256 in any products.
Package: openstack-nova (Red Hat OpenStack Platform 3) - Not affected
Package: openstack-nova (Red Hat OpenStack Platform 4) - Not affected
Debian
CVE-2013-4278: nova - The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Ha...
vendor_debian·2013·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278: nova - The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Ha...
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Scope: local
bookworm: resolved (fixed in 2013.1.3-1)
bullseye: resolved (fixed in 2013.1.3-1)
forky: resolved (fixed in 2013.1.3-1)
sid: resolved (fixed in 2013.1.3-1)
trixie: resolved (fixed in 2013.1.3-1)
GHSA
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
ghsa·2022-05-17·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
OSV
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
osv·2022-05-17·CVSS 6.0
CVE-2013-4278 [MEDIUM] OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
OSV
CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property
osv·2013-09-16·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4279 imapsync default version check with http://imapsync.lamiral.info information leakage
bugzilla·2013-08-23·CVSS 3.5
CVE-2013-4279 [LOW] CVE-2013-4279 imapsync default version check with http://imapsync.lamiral.info information leakage
CVE-2013-4279 imapsync default version check with http://imapsync.lamiral.info information leakage
Kurt Seifried ([email protected]) reports:
Title: imapsync default version check with http://imapsync.lamiral.info information leakage (CVE-2013-4278)
Threat: Availability: no timeout so an attacker simply sends a slow response
Threat: Confidentiality: connects to http://imapsync.lamiral.info and sends version # and operating system name and person version
Impact: Moderate (Medium)
CVSS2: 5.8/AV:N/AC:M/Au:N/C:P/I:N/A:P
Affected: imapsync version 1.564 and earlier on all supported platforms
Description: By default imapsync runs a "release check" when executed, this causes imapsync to connect to http://imapsync.lamiral.info and send information about the version of imapsync, the operat
Bugzilla
CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
CVE-2013-4278 OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256
Vincent Danen ([email protected]) reports:
The previous fix was insufficient and did not fully fix the flaw, as noted here:
https://bugs.launchpad.net/ossa/+bug/1212179
The patch to fully correct this flaw is here (I believe it would be in addition to previously-mentioned patches):
https://github.com/openstack/nova/commit/4054cc4a22a1fea997dec76afb5646fd6c6ea6b9
Discussion:
Created openstack-nova tracking bugs for this issue:
Affects: fedora-all [bug 1000087]
Affects: epel-6 [bug 1000088]
---
Statement:
Not vulnerable. Red Hat did not release the incomplete fix for CVE-2013-2256 in any products.
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bo
Bugzilla
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
bugzilla·2013-08-22·CVSS 6.0
CVE-2013-4278 [MEDIUM] CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
CVE-2013-4278 openstack-nova: OpenStack: Nova private flavors resource limit circumvention incomplete fix for CVE-2013-2256 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bod
http://lists.openstack.org/pipermail/openstack-announce/2013-August/000138.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1199.htmlhttps://bugs.launchpad.net/ossa/+bug/1212179http://lists.openstack.org/pipermail/openstack-announce/2013-August/000138.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1199.htmlhttps://bugs.launchpad.net/ossa/+bug/1212179
2013-09-16
Published