CVE-2013-4278: Low severity openstack compute (nova) vulnerability
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:ispublic property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4278?
CVE-2013-4278 is considered a medium severity vulnerability.
How do I fix CVE-2013-4278?
To fix CVE-2013-4278, upgrade OpenStack Compute (Nova) to version 12.0.0a0 or later.
What systems are affected by CVE-2013-4278?
CVE-2013-4278 affects OpenStack Compute (Nova) versions Folsom, Grizzly, and Havana.
What is the impact of CVE-2013-4278?
CVE-2013-4278 allows remote authenticated users to boot arbitrary flavors by guessing flavor IDs, potentially leading to unauthorized access.
Is there a workaround for CVE-2013-4278?
There is no known workaround for CVE-2013-4278 other than applying the recommended upgrade.