VDB
CVE-2013-4497
CVE-2013-4497
PUBLISHED
CVSS 6.400000095367432 MEDIUM
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
EPSS 0.21% · 43.5th percentile
Risk Scores
CVSS 2.0
6.400000095367432
EPSS Score
0.21%
43.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| PyPI | nova | 0 |
| openstack | havana | havana-2, 0, havana-1 |
| openstack | folsom | |
| openstack | grizzly |
Timeline
- Nov 5, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 8, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- [oss-security] 20131103 CVE request for a vulnerability in OpenStack Nova mailing-list
- https://bugs.launchpad.net/nova/+bug/1202266 url
- [oss-security] 20131103 Re: CVE request for a vulnerability in OpenStack Nova mailing-list
- https://bugs.launchpad.net/nova/+bug/1073306 url
- https://nvd.nist.gov/vuln/detail/CVE-2013-4497 advisory
- https://github.com/openstack/nova/commit/01de658210fd65171bfbf5450c93673b5ce0bd9e url
- https://github.com/openstack/nova/commit/5cced7a6dd32d231c606e25dbf762d199bf9cca7 url
- https://github.com/openstack/nova/commit/ba0d007fb78bd1182c3c0b808dbd7ccc84640e80 url
- https://github.com/openstack/nova/commit/df2ea2e3acdede21b40d47b7adbeac04213d031b url
- https://github.com/openstack/nova package