Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0167


The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.


Published

2014-04-15T14:55:04.200

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack compute 2013.1 Yes
Application openstack compute 2013.1.1 Yes
Application openstack compute 2013.1.2 Yes
Application openstack compute 2013.1.3 Yes
Application openstack compute 2013.2 Yes
Application openstack compute 2013.2.1 Yes
Application openstack compute 2013.2.2 Yes
Application openstack compute 2013.2.3 Yes
Application openstack icehouse - Yes

References