Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2013-2030
Disclosure Date: December 27, 2013 (last updated October 05, 2023)
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
0
Attacker Value
Unknown
CVE-2013-4497
Disclosure Date: November 05, 2013 (last updated October 05, 2023)
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
0
Attacker Value
Unknown
CVE-2013-4179
Disclosure Date: September 16, 2013 (last updated November 08, 2023)
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
0
Attacker Value
Unknown
CVE-2013-2161
Disclosure Date: August 20, 2013 (last updated October 05, 2023)
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
0
Attacker Value
Unknown
CVE-2013-4155
Disclosure Date: August 20, 2013 (last updated October 05, 2023)
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
0