CVE-2013-6419
published 2014-01-07CVE-2013-6419: Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.84%
76.6th percentile
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2013.2.1-1 (bookworm) | neutron 2013.2.1-1 (bookworm) |
| debian | nova | < neutron 2013.2.1-1 (bookworm) | neutron 2013.2.1-1 (bookworm) |
| openstack | havana | <= havana-1 | — |
| openstack | neutron | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | neutron | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | neutron | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | neutron | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | nova | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | nova | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | nova | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | nova | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova Router metadata queries are not restricted by tenant
osv·2022-05-17
CVE-2013-6419 [MEDIUM] OpenStack Nova Router metadata queries are not restricted by tenant
OpenStack Nova Router metadata queries are not restricted by tenant
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (`agent/metadata/agent.py`) in Neutron.
GHSA
OpenStack Nova Router metadata queries are not restricted by tenant
ghsa·2022-05-17
CVE-2013-6419 [MEDIUM] CWE-200 OpenStack Nova Router metadata queries are not restricted by tenant
OpenStack Nova Router metadata queries are not restricted by tenant
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (`agent/metadata/agent.py`) in Neutron.
OSV
CVE-2013-6419: Interaction error in OpenStack Nova and Neutron before Havana 2013
osv·2014-01-07·CVSS 5.0
CVE-2013-6419 [MEDIUM] CVE-2013-6419: Interaction error in OpenStack Nova and Neutron before Havana 2013
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Red Hat
Nova: Metadata queries from Neutron to Nova are not restricted by tenant
vendor_redhat·2013-12-11·CVSS 5.0
CVE-2013-6419 [MEDIUM] Nova: Metadata queries from Neutron to Nova are not restricted by tenant
Nova: Metadata queries from Neutron to Nova are not restricted by tenant
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Debian
CVE-2013-6419: neutron - Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and iceho...
vendor_debian·2013·CVSS 5.0
CVE-2013-6419 [MEDIUM] CVE-2013-6419: neutron - Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and iceho...
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Scope: local
bookworm: resolved (fixed in 2013.2.1-1)
bullseye: resolved (fixed in 2013.2.1-1)
forky: resolved (fixed in 2013.2.1-1)
sid: resolved (fixed in 2013.2.1-1)
trixie: resolved (fixed in 2013.2.1-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0091.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0231.htmlhttp://www.openwall.com/lists/oss-security/2013/12/11/8http://www.securityfocus.com/bid/64250https://bugs.launchpad.net/neutron/+bug/1235450https://review.openstack.org/#/c/61428/2/nova/api/metadata/handler.pyhttps://review.openstack.org/#/c/61439/1/neutron/agent/metadata/agent.pyhttp://rhn.redhat.com/errata/RHSA-2014-0091.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0231.htmlhttp://www.openwall.com/lists/oss-security/2013/12/11/8http://www.securityfocus.com/bid/64250https://bugs.launchpad.net/neutron/+bug/1235450https://review.openstack.org/#/c/61428/2/nova/api/metadata/handler.pyhttps://review.openstack.org/#/c/61439/1/neutron/agent/metadata/agent.py
2014-01-07
Published