CVE-2015-2687: Medium severity openstack compute (nova) vulnerability
It was reported that under certain conditions (when live migrations fails), an attacker can access other VMs volumes, which under normal conditions he should not be able to access: https://bugs.launchpad.net/nova/+bug/1419577
CVE has been assigned here: http://seclists.org/oss-sec/2015/q1/990 No patches are available at the time of writing.
Other sources
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2687?
CVE-2015-2687 is rated as a medium severity vulnerability due to its potential to allow unauthorized access to other VMs' volumes.
How do I fix CVE-2015-2687?
To fix CVE-2015-2687, upgrade to a version of OpenStack Compute newer than 15.0.0.0b1.
What versions of OpenStack Compute are affected by CVE-2015-2687?
CVE-2015-2687 affects OpenStack Compute versions 2013.2 through 2014.2.4.
What type of attack does CVE-2015-2687 enable?
CVE-2015-2687 enables attackers to access the volumes of other virtual machines under certain conditions during live migration failures.
Is CVE-2015-2687 specific to any deployment environment?
CVE-2015-2687 primarily affects deployments of OpenStack using the Compute component.