Instance Rescue Mode Vulnerability in OpenStack Compute by OpenStack
CVE-2014-0134

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
8 May 2014

Summary

The instance rescue mode in OpenStack Compute (Nova) versions 2013.2 prior to 2013.2.3 and Icehouse before 2014.1 has a vulnerability that allows remote authenticated users to access sensitive compute host files. This occurs due to an improper handling of image spawning with configured settings, where the use_cow_images option is disabled. Attackers can exploit this issue by providing a crafted image that, when used to overwrite an instance disk, exposes critical host files that should remain secure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.