CVE-2017-16239: Medium severity Openstack Nova vulnerability
By rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected.
Affected versions: <=14.0.9, >=15.0.0 <=15.0.7, >=16.0.0 <=16.0.2
Bug report:
https://launchpad.net/bugs/1664931
Other sources
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/novato a version that resolves this vulnerability.Fixed in 2:18.1.0-6Fixed in 2:18.1.0-6+deb10u2Fixed in 2:22.0.1-2+deb11u1Fixed in 2:26.1.0-4Fixed in 2:28.0.0-2 - Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 14.0.10 - Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 15.0.8 - Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 16.0.3 - Upgrade
Upgrade
OpenStack Nova (Filter Scheduler)to a version that resolves this vulnerability.Fixed in 14.0.10 - Upgrade
Upgrade
OpenStack Nova (Filter Scheduler)to a version that resolves this vulnerability.Fixed in 15.0.8 - Upgrade
Upgrade
OpenStack Nova (Filter Scheduler)to a version that resolves this vulnerability.Fixed in 16.0.3
Event History
Frequently Asked Questions
What is CVE-2017-16239?
CVE-2017-16239 is a vulnerability in OpenStack Nova that allows an authenticated user to bypass imposed filters by rebuilding an instance.
What is the severity of CVE-2017-16239?
The severity of CVE-2017-16239 is medium with a CVSS score of 6.5.
How does CVE-2017-16239 affect OpenStack Nova?
CVE-2017-16239 affects OpenStack Nova versions 14.0.9 through 16.0.2.
How can an authenticated user exploit CVE-2017-16239?
An authenticated user can exploit CVE-2017-16239 by rebuilding an instance, which allows them to bypass imposed filters like the ImagePropertiesFilter or the IsolatedHostsFilter.
Is there a fix available for CVE-2017-16239?
Yes, the fix for CVE-2017-16239 is available in the following versions: 2:18.1.0-6, 2:18.1.0-6+deb10u2, 2:22.0.1-2+deb11u1, 2:26.1.0-4, and 2:28.0.0-2.