CVE-2013-0208: Medium severity red hat openstack essex vulnerability
Russel Bryant rbryant reports on behalf of the OpenStack Project:
Title: Boot from volume allows access to random volumes Reporter: Phil Day (HP) Products: Nova Affects: Essex, Folsom
Description: Phil Day from HP reported a vulnerability in volume attachment in nova-volume, affecting the boot-from-volume feature. By passing a specific volume ID, an authenticated user may be able to boot from a volume he doesn't own, potentially resulting in full access to that 3rd-party volume contents. Folsom setups making use of Cinder are not affected.
Proposed patches: See attached patches for the Folsom and Essex series. Unless a flaw is discovered in them, these proposed patches will be merged to Nova stable/folsom and stable/essex branches on the public disclosure date.
Other sources
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the blockdevicemapping parameter.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0208?
CVE-2013-0208 is classified as a high severity vulnerability.
How do I fix CVE-2013-0208?
To mitigate CVE-2013-0208, it is recommended to upgrade to a patched version of OpenStack.
What products are affected by CVE-2013-0208?
CVE-2013-0208 affects OpenStack versions Essex and Folsom, as well as specific Ubuntu releases.
What type of vulnerability is CVE-2013-0208?
CVE-2013-0208 is a vulnerability related to improper access control in volume attachment.
Who reported CVE-2013-0208?
CVE-2013-0208 was reported by Phil Day on behalf of the OpenStack Project.