7.6

CVE-2013-0335

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenstackEssex Version2012.1
OpenstackFolsom Version2012.2
OpenstackGrizzly Version2012.2
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.12% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

http://secunia.com/advisories/52337
Vendor Advisory
http://secunia.com/advisories/52728
Vendor Advisory
http://www.openwall.com/lists/oss-security/2013/02/26/7
http://www.osvdb.org/90657
https://bugs.launchpad.net/nova/+bug/1125378
https://review.openstack.org/#/c/22086/
https://review.openstack.org/#/c/22758
https://review.openstack.org/#/c/22872/
http://rhn.redhat.com/errata/RHSA-2013-0709.html
http://www.ubuntu.com/usn/USN-1771-1
https://access.redhat.com/errata/RHSA-2013:0709
https://access.redhat.com/security/cve/CVE-2013-0335
https://github.com/advisories/GHSA-qfp8-hfqx-c79c