OpenStack Havana Havana-2

CPE Details

OpenStack Havana Havana-2
havana-2
2013-09-17
12h58 +00:00
2013-09-23
11h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openstack:havana:havana-2:*:*:*:*:*:*:*

Informations

Vendor

openstack

Product

havana

Version

havana-2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-2030 2013-12-27 00h00 +00:00 keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
2.1
CVE-2013-4497 2013-11-05 20h00 +00:00 The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
6.4
CVE-2013-4179 2013-09-16 17h00 +00:00 The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
4.3