6

CVE-2014-0167

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenstackCompute Version2013.1
OpenstackCompute Version2013.1.1
OpenstackCompute Version2013.1.2
OpenstackCompute Version2013.1.3
OpenstackCompute Version2013.2
OpenstackCompute Version2013.2.1
OpenstackCompute Version2013.2.2
OpenstackCompute Version2013.2.3
OpenstackIcehouse Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.566
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P