CVE-2015-2687Improper Access Control in Nova

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 84.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateMay 17

Description

OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

PyPIopenstack/nova< 15.0.0.0b1
Debianopenstack/nova< 2014.1-1+3
NVDopenstack/compute16 versions+15

🔴Vulnerability Details

4
OSV
OpenStack Compute (Nova) Improper Access Control2022-05-17
GHSA
OpenStack Compute (Nova) Improper Access Control2022-05-17
CVEList
CVE-2015-2687: OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have2017-08-09
OSV
CVE-2015-2687: OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have2017-08-09

📋Vendor Advisories

2
Red Hat
openstack-nova: information leak when live-migration failed2015-02-19
Debian
CVE-2015-2687: nova - OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails all...2015

💬Community

2
Bugzilla
CVE-2015-2687 openstack-nova: information leak when live-migration failed2015-03-24
Bugzilla
CVE-2015-2687 openstack-nova: information leak when live-migration failed [fedora-all]2015-03-24
CVE-2015-2687 — Improper Access Control in Nova | cvebase