6

CVE-2014-0167

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.

Data is provided by the National Vulnerability Database (NVD)
OpenstackCompute Version2013.1
OpenstackCompute Version2013.1.1
OpenstackCompute Version2013.1.2
OpenstackCompute Version2013.1.3
OpenstackCompute Version2013.2
OpenstackCompute Version2013.2.1
OpenstackCompute Version2013.2.2
OpenstackCompute Version2013.2.3
OpenstackIcehouse Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.566
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P