Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2013-2030

Disclosure Date: December 27, 2013 (last updated October 05, 2023)
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
0
Attacker Value
Unknown

CVE-2013-4497

Disclosure Date: November 05, 2013 (last updated October 05, 2023)
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
0
Attacker Value
Unknown

CVE-2013-4179

Disclosure Date: September 16, 2013 (last updated November 08, 2023)
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
0
Attacker Value
Unknown

CVE-2013-2161

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
0
Attacker Value
Unknown

CVE-2013-4155

Disclosure Date: August 20, 2013 (last updated October 05, 2023)
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
0