Safety vulnerability ID: 35599
The information on this page was manually curated by our Cybersecurity Intelligence Team.
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
Latest version: 30.0.0
Cloud computing fabric controller
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
MLIST:[openstack-announce] 20150313 [OSSA 2015-005] Nova console Cross-Site WebSocket hijacking (CVE-2015-0259): http://lists.openstack.org/pipermail/openstack-announce/2015-March/000341.html
CONFIRM:https://bugs.launchpad.net/nova/+bug/1409142: https://bugs.launchpad.net/nova/+bug/1409142
REDHAT:RHSA-2015:0790: http://rhn.redhat.com/errata/RHSA-2015-0790.html
REDHAT:RHSA-2015:0843: http://rhn.redhat.com/errata/RHSA-2015-0843.html
REDHAT:RHSA-2015:0844: http://rhn.redhat.com/errata/RHSA-2015-0844.html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application