CVE-2013-0335: Openstack nova: vnc proxy can connect to the wrong vm
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Novato a version that resolves this vulnerability.Fixed in 12.0.0a0
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0335?
CVE-2013-0335 is considered a medium severity vulnerability due to the potential unauthorized access it provides.
How do I fix CVE-2013-0335?
To fix CVE-2013-0335, upgrade your OpenStack Nova installation to version 12.0.0a0 or later.
Which versions of OpenStack are affected by CVE-2013-0335?
CVE-2013-0335 affects OpenStack Compute (Nova) releases Grizzly, Folsom, and Essex.
Can remote authenticated users exploit CVE-2013-0335?
Yes, remote authenticated users can exploit CVE-2013-0335 to gain access to a VM using a VNC token.
What is the impact of CVE-2013-0335 on cloud security?
The impact of CVE-2013-0335 on cloud security includes the risk of unauthorized access to VMs, potentially compromising sensitive data.