CVE-2013-4497
published 2013-11-05CVE-2013-4497: The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or…
PriorityP335medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.81%
76.1th percentile
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.2-1 (bookworm) | nova 2013.2-1 (bookworm) |
| openstack | havana | <= havana-3 | — |
| openstack | havana | — | — |
| openstack | havana | — | — |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Compute Nova Improper Access Control
ghsa·2022-05-17
CVE-2013-4497 [MEDIUM] OpenStack Compute Nova Improper Access Control
OpenStack Compute Nova Improper Access Control
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
OSV
OpenStack Compute Nova Improper Access Control
osv·2022-05-17
CVE-2013-4497 [MEDIUM] OpenStack Compute Nova Improper Access Control
OpenStack Compute Nova Improper Access Control
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
OSV
CVE-2013-4497: The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013
osv·2013-11-05·CVSS 6.4
CVE-2013-4497 [MEDIUM] CVE-2013-4497: The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Debian
CVE-2013-4497: nova - The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana befor...
vendor_debian·2013·CVSS 6.4
CVE-2013-4497 [MEDIUM] CVE-2013-4497: nova - The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana befor...
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Scope: local
bookworm: resolved (fixed in 2013.2-1)
bullseye: resolved (fixed in 2013.2-1)
forky: resolved (fixed in 2013.2-1)
sid: resolved (fixed in 2013.2-1)
trixie: resolved (fixed in 2013.2-1)
Red Hat
openstack-nova: XenAPI security groups not kept through migrate or resize
vendor_redhat·2012-10-30·CVSS 6.4
CVE-2013-4497 [MEDIUM] openstack-nova: XenAPI security groups not kept through migrate or resize
openstack-nova: XenAPI security groups not kept through migrate or resize
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize [fedora-all]
bugzilla·2013-11-04·CVSS 6.4
CVE-2013-4497 [MEDIUM] CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize [fedora-all]
CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize
bugzilla·2013-11-04·CVSS 6.4
CVE-2013-4497 [MEDIUM] CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize
CVE-2013-4497 openstack-nova: XenAPI security groups not kept through migrate or resize
Jeremy Stanley reports:
Chris Behrens with Rackspace and Vangelis Tasoulas reported a set of
vulnerabilities in OpenStack Nova. When migrating or resizing an
instance, including live migration, existing security groups may not
be reapplied after the operation completes. This can lead to
unintentional network exposure for virtual machines. Only setups
using the XenAPI backend are affected.
Discussion:
Created openstack-nova tracking bugs for this issue:
Affects: fedora-all [bug 1026175]
---
External References:
https://launchpad.net/bugs/1073306
https://launchpad.net/bugs/1202266
---
Upstream fixes:
https://review.openstack.org/52987
https://review.openstack.org/52991
---
Created attachment
http://www.openwall.com/lists/oss-security/2013/11/03/2http://www.openwall.com/lists/oss-security/2013/11/03/3https://bugs.launchpad.net/nova/+bug/1073306https://bugs.launchpad.net/nova/+bug/1202266http://www.openwall.com/lists/oss-security/2013/11/03/2http://www.openwall.com/lists/oss-security/2013/11/03/3https://bugs.launchpad.net/nova/+bug/1073306https://bugs.launchpad.net/nova/+bug/1202266
2013-11-05
Published