Access Restriction Bypass in OpenStack Nova by Canonical
CVE-2012-0030

Currently unrated

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
13 January 2012

What is CVE-2012-0030?

The vulnerability in OpenStack Nova versions 2011.3 and Essex allows remote authenticated users to bypass access restrictions for other tenants. This is achieved through an OSAPI request where the project_id URI parameter can be modified, potentially granting unauthorized access to sensitive data. Such a flaw could severely compromise the security model of tenant isolation within the cloud environment.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.