GHSA-p258-xmh3-72pv

Suggest an improvement
Source
https://github.com/advisories/GHSA-p258-xmh3-72pv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-p258-xmh3-72pv
Aliases
Published
2022-05-17T04:41:34Z
Modified
2023-11-01T04:45:26.687209Z
Summary
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
Details

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) addrules, (2) removerules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.

Database specific
{
    "nvd_published_at": "2014-04-15T14:55:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-02-08T18:04:25Z"
}
References

Affected packages

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2013.1.0
Fixed
2013.2.4