CVE-2013-2256: Medium severity openstack compute (nova) vulnerability
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:ispublic property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2256?
CVE-2013-2256 is considered a medium severity vulnerability due to its potential to expose sensitive information and allow unauthorized access.
How do I fix CVE-2013-2256?
To remediate CVE-2013-2256, upgrade your OpenStack Nova version to at least 2013.1.3 or any version after Havana-2.
What systems are affected by CVE-2013-2256?
CVE-2013-2256 affects OpenStack Compute (Nova) versions prior to 2013.1.3 and the Havana release before havana-2.
What impact does CVE-2013-2256 have on exposed systems?
CVE-2013-2256 can allow remote authenticated users to access sensitive flavor properties and boot arbitrary flavors, posing security risks.
Who is primarily affected by CVE-2013-2256?
Organizations using vulnerable versions of OpenStack Nova are primarily affected by CVE-2013-2256 due to potential unauthorized access.