7.6

CVE-2013-0335

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Essex Version 2012.1
Openstack ≫ Folsom Version 2012.2
Openstack ≫ Grizzly Version 2012.2
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.12% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

http://secunia.com/advisories/52337
Vendor Advisory
http://secunia.com/advisories/52728
Vendor Advisory
http://www.openwall.com/lists/oss-security/2013/02/26/7
http://www.osvdb.org/90657
https://bugs.launchpad.net/nova/+bug/1125378
https://review.openstack.org/#/c/22086/
https://review.openstack.org/#/c/22758
https://review.openstack.org/#/c/22872/
http://rhn.redhat.com/errata/RHSA-2013-0709.html
http://www.ubuntu.com/usn/USN-1771-1
https://access.redhat.com/errata/RHSA-2013:0709
https://access.redhat.com/security/cve/CVE-2013-0335
https://github.com/advisories/GHSA-qfp8-hfqx-c79c