Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2013-4261
Disclosure Date: October 29, 2013 (last updated October 05, 2023)
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
0
Attacker Value
Unknown
CVE-2012-6120
Disclosure Date: April 10, 2013 (last updated October 05, 2023)
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
0
Attacker Value
Unknown
CVE-2013-1815
Disclosure Date: April 10, 2013 (last updated October 05, 2023)
PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file.
0