Safety vulnerability ID: 35507
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 32.1.0
Cloud computing fabric controller
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.
MLIST:[oss-security] 20140409 [OSSA 2014-011] RBAC policy not properly enforced in Nova EC2 API (CVE-2014-0167): http://www.openwall.com/lists/oss-security/2014/04/09/26
CONFIRM:https://launchpad.net/bugs/1290537: https://launchpad.net/bugs/1290537
UBUNTU:USN-2247-1: http://www.ubuntu.com/usn/USN-2247-1
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application