Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
2012-01-13T18:55:04.157
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.9 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:P
6.8
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | essex | * | Yes |
Application | openstack | nova | 2011.3 | Yes |