CVE-2013-7048: Low severity Openstack Nova vulnerability
OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 12.0.0a0
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7048?
CVE-2013-7048 is considered a moderate severity vulnerability due to its potential for local users to read and modify sensitive live snapshots.
How do I fix CVE-2013-7048?
To fix CVE-2013-7048, upgrade to OpenStack Nova version 12.0.0a0 or later.
What are the affected versions for CVE-2013-7048?
CVE-2013-7048 affects OpenStack Compute (Nova) version 2013.1.4, 2013.2.1, and earlier versions.
What type of permissions are involved in CVE-2013-7048?
CVE-2013-7048 involves world-writable and world-readable permissions for the temporary directory used for live snapshots.
Can CVE-2013-7048 be exploited by remote users?
No, CVE-2013-7048 can only be exploited by local users with access to the system.