OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
2015-04-01T14:59:01.380
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.1 (MEDIUM)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | nova | < 2014.1.4 | Yes |
Application | openstack | nova | < 2014.2.3 | Yes |
Application | openstack | nova | 2015.1.0 | Yes |
Application | openstack | nova | 2015.1.0 | Yes |