CVE-2014-0167: Medium severity Openstack Compute vulnerability
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) addrules, (2) removerules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.
Other sources
Tristan Cacqueray reports:
Title: RBAC policy not properly enforced in Nova EC2 API Reporter: Marc Heckmann (Ubisoft) Products: Nova Versions: 2013.1 versions up to 2013.2.3
Description: Marc Heckmann from Ubisoft reported a vulnerability in the Nova EC2 API security group implementation. RBAC policies are not enforced when using the EC2 API, in particular the addrules, removerules and destroy methods. A restricted user may overcome his limitation by using EC2 API resulting in unauthorized action on security groups. Only setups using non-default RBAC rules for Nova may be affected.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 2013.2.4 - Upgrade
Upgrade
OpenStack Compute (Nova)to a version that resolves this vulnerability.Fixed in 2013.2.4 - Upgrade
Upgrade
OpenStack Compute (Nova) (Icehouse)to a version that resolves this vulnerability.Patch icehouse-rc2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0167?
CVE-2014-0167 has a moderate severity level as it can lead to unauthorized access to security group modifications.
How do I fix CVE-2014-0167?
To fix CVE-2014-0167, upgrade your OpenStack Compute to the version 2013.2.4 or later, or Icehouse-rc2 or later.
What software versions are affected by CVE-2014-0167?
CVE-2014-0167 affects OpenStack Compute versions 2013.1 through 2013.2.3 and all versions of Icehouse prior to Icehouse-rc2.
What component does CVE-2014-0167 impact within OpenStack?
CVE-2014-0167 impacts the Nova EC2 API security group implementation within OpenStack Compute.
Are there workarounds for CVE-2014-0167 if upgrading is not immediately possible?
There are no reliable workarounds; the recommended action is to upgrade to a secure version as soon as possible.