CVE-2013-2030
Published Dec 27, 2013
Last updated 11 years ago
Overview
- Description
- keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openstack:compute:2013.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DE1DE9A-0D08-448B-AF80-7ACA236F2A83" }, { "criteria": "cpe:2.3:a:openstack:compute:2013.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1A5AAEB-0A8F-4ECF-B184-6A78B882817A" }, { "criteria": "cpe:2.3:a:openstack:compute:2013.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8596FDB-87DD-4D06-9923-75EFE7E3F9A0" }, { "criteria": "cpe:2.3:a:openstack:compute:2013.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA06A9A5-0924-4137-85AF-DB9C7C246DAC" }, { "criteria": "cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5BA13BC-F088-45AA-AD10-B74F89CE5375" }, { "criteria": "cpe:2.3:a:openstack:grizzly:2013.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53AAF5DD-EB6C-4EB8-874B-949D74B34179" }, { "criteria": "cpe:2.3:a:openstack:havana:havana-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45762277-1BC6-4552-B5AB-756AE8D9F543" }, { "criteria": "cpe:2.3:a:openstack:havana:havana-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "588B9906-F0A0-4109-94D9-11481135ED06" }, { "criteria": "cpe:2.3:a:openstack:havana:havana-3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C6D7CB3-7FFB-4F2C-80A8-9568D3868EB6" } ], "operator": "OR" } ] } ]