Vulnerability Name: | CVE-2013-7048 (CCN-89873) | ||||||||
Assigned: | 2013-09-18 | ||||||||
Published: | 2013-09-18 | ||||||||
Updated: | 2018-11-16 | ||||||||
Summary: | OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N) 2.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-7048 Source: CCN Type: oss-security mailing list Wed, 11 Dec 2013 15:43:30 +0100 CVE request for a vulnerability in OpenStack Nova Source: REDHAT Type: Third Party Advisory RHSA-2014:0231 Source: CCN Type: SA56088 OpenStack Compute (Nova) Live Snapshots Insecure Permissions Security Issue Source: CCN Type: IBM Security Bulletin 1668758 Nova live snapshots use an insecure local directory (CVE-2013-7048) Source: CCN Type: OpenStack Compute Web Site OpenStack Compute Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20140113 [OSSA 2014-001] Nova live snapshots use an insecure local directory (CVE-2013-7048) Source: CCN Type: BID-64266 OpenStack Compute (Nova) CVE-2013-7048 Insecure Directory Permissions Vulnerability Source: CONFIRM Type: Exploit, Patch, Third Party Advisory https://bugs.launchpad.net/nova/+bug/1227027 Source: XF Type: UNKNOWN openstack-cve20137048-info-disclosure(89873) Source: CCN Type: OpenStack Compute Grizzly GIT Repository Web Site Change I767ff524: Enforce permissions in snapshots temporary dir Source: CCN Type: OpenStack Compute Havana GIT Repository Web Site Change I767ff524: Enforce permissions in snapshots temporary dir | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |