LWN.net Logo

nova: access control bypass

Package(s):nova CVE #(s):CVE-2012-0030
Created:January 11, 2012 Updated:January 20, 2012
Description: From the Ubuntu advisory: Nachi Ueno, Rohit Karajgi, and Venkatesan Ravikumar discovered that when Nova is configured to use the OpenStack API, it would not correctly enforce access controls on certain incoming requests. A remote authenticated attacker could exploit this to change resources of arbitrary tenants.
Alerts:
Ubuntu USN-1326-1 2012-01-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds