REDHAT-BUG-1205313: Low severity openstack compute (nova) vulnerability
It was reported that under certain conditions (when live migrations fails), an attacker can access other VMs volumes, which under normal conditions he should not be able to access: https://bugs.launchpad.net/nova/+bug/1419577
CVE has been assigned here: http://seclists.org/oss-sec/2015/q1/990 No patches are available at the time of writing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1205313?
The severity of REDHAT-BUG-1205313 is considered high due to the potential unauthorized access to virtual machine volumes.
How do I fix REDHAT-BUG-1205313?
To fix REDHAT-BUG-1205313, administrators should apply the latest patches from OpenStack for the Nova component.
Which versions of OpenStack Nova are affected by REDHAT-BUG-1205313?
REDHAT-BUG-1205313 affects the OpenStack Nova versions where live migration vulnerabilities exist, primarily earlier releases.
What are the risks associated with REDHAT-BUG-1205313?
The risks associated with REDHAT-BUG-1205313 include potential data leaks and unauthorized access to other virtual machines during migration failures.
Can REDHAT-BUG-1205313 be exploited remotely?
Yes, REDHAT-BUG-1205313 can potentially be exploited remotely if an attacker has access to exploit the live migration failure scenario.