CVE-2013-6419: Infoleak
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Other sources
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 12.0.0a0
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6419?
CVE-2013-6419 has a medium severity level due to the potential for remote tenants to access sensitive metadata.
How do I fix CVE-2013-6419?
To fix CVE-2013-6419, upgrade to OpenStack Nova version 12.0.0a0 or higher and ensure proper tenant ID validation.
Which versions of OpenStack are affected by CVE-2013-6419?
CVE-2013-6419 affects OpenStack versions prior to Havana 2013.2.1 and Icehouse-1.
What vulnerabilities does CVE-2013-6419 expose?
CVE-2013-6419 exposes sensitive tenant metadata to unauthorized remote tenants due to improper validation of instance IDs.
Is CVE-2013-6419 still a concern for current OpenStack deployments?
CVE-2013-6419 is not a concern for current OpenStack deployments using versions above Havana 2013.2.1.