CVE-2013-4497 Information
Feb 14, 2021
cve
Description
The XenAPI backend in OpenStack Compute (Nova) Folsom Grizzly and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration which allows remote attackers to bypass intended restrictions.
Reference
http://www.openwall.com/lists/oss-security/2013/11/03/2 http://www.openwall.com/lists/oss-security/2013/11/03/3 https://bugs.launchpad.net/nova/+bug/1073306 https://bugs.launchpad.net/nova/+bug/1202266
Share on: