First published: Sun Jul 22 2012(Updated: )
Directory traversal vulnerability in `virt/disk/api.py` in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Essex | =2012.1 | |
OpenStack Folsom | =2012.2 | |
pip/nova | <12.0.0a0 | 12.0.0a0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.