Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-7130


The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.


Published

2014-02-06T17:00:06.977

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack compute 2012.2 Yes
Application openstack compute 2013.1 Yes
Application openstack compute 2013.1.1 Yes
Application openstack compute 2013.1.2 Yes
Application openstack compute 2013.1.3 Yes
Application openstack grizzly - Yes
Application openstack havana - Yes
Application openstack icehouse - Yes

References