CVE-2011-4596: Path Traversal
Published Dec 23, 2011
·Updated
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
Affected Software
2 affected componentsFixes available
pip/nova<12.0.0a0
12.0.0a0
Openstack Nova>=2011.3<2011.3.1
Event History
Dec 23, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-4596?
CVE-2011-4596 is classified as a medium severity vulnerability allowing remote authenticated users to overwrite arbitrary files.
2
How do I fix CVE-2011-4596?
To fix CVE-2011-4596, upgrade to OpenStack Nova version 2011.3.1 or later.
3
What causes the vulnerability CVE-2011-4596?
CVE-2011-4596 is caused by multiple directory traversal vulnerabilities in OpenStack Nova when certain APIs are enabled.
4
Which versions of OpenStack Nova are affected by CVE-2011-4596?
OpenStack Nova versions before 2011.3.1 are affected by CVE-2011-4596.
5
Can CVE-2011-4596 be exploited without authentication?
No, CVE-2011-4596 can only be exploited by remote authenticated users.