CVE-2013-0208: Medium severity red hat openstack essex vulnerability

Published Jan 22, 2013
·
Updated

Russel Bryant rbryant reports on behalf of the OpenStack Project:

Title: Boot from volume allows access to random volumes Reporter: Phil Day (HP) Products: Nova Affects: Essex, Folsom

Description: Phil Day from HP reported a vulnerability in volume attachment in nova-volume, affecting the boot-from-volume feature. By passing a specific volume ID, an authenticated user may be able to boot from a volume he doesn't own, potentially resulting in full access to that 3rd-party volume contents. Folsom setups making use of Cinder are not affected.

Proposed patches: See attached patches for the Folsom and Essex series. Unless a flaw is discovered in them, these proposed patches will be merged to Nova stable/folsom and stable/essex branches on the public disclosure date.

Other sources

The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the blockdevicemapping parameter.

MITRE

Affected Software

5 affected components
Openstack Essex
Openstack folsom
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10

Event History

Jan 22, 2013
Data Sourced
06:17 AM
DescriptionSeverityAffected Software
Feb 13, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-0208?

CVE-2013-0208 is classified as a high severity vulnerability.

2

How do I fix CVE-2013-0208?

To mitigate CVE-2013-0208, it is recommended to upgrade to a patched version of OpenStack.

3

What products are affected by CVE-2013-0208?

CVE-2013-0208 affects OpenStack versions Essex and Folsom, as well as specific Ubuntu releases.

4

What type of vulnerability is CVE-2013-0208?

CVE-2013-0208 is a vulnerability related to improper access control in volume attachment.

5

Who reported CVE-2013-0208?

CVE-2013-0208 was reported by Phil Day on behalf of the OpenStack Project.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203