CVE-2012-0030: Medium severity Openstack Essex vulnerability
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified projectid URI parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0030?
CVE-2012-0030 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2012-0030?
To mitigate CVE-2012-0030, upgrade to a patched version of OpenStack Nova or Essex that addresses this vulnerability.
Who is affected by CVE-2012-0030?
CVE-2012-0030 affects users of OpenStack Nova 2011.3 and Essex using the OpenStack API.
What specifically does CVE-2012-0030 allow attackers to do?
CVE-2012-0030 allows remote authenticated users to bypass access restrictions and potentially access other users' tenant data.
Is there a workaround for CVE-2012-0030?
A temporary workaround for CVE-2012-0030 is to implement additional access controls at the network level until a patch is applied.