Instance Rescue Mode Vulnerability in OpenStack Compute by OpenStack
CVE-2014-0134
Currently unrated
Summary
The instance rescue mode in OpenStack Compute (Nova) versions 2013.2 prior to 2013.2.3 and Icehouse before 2014.1 has a vulnerability that allows remote authenticated users to access sensitive compute host files. This occurs due to an improper handling of image spawning with configured settings, where the use_cow_images option is disabled. Attackers can exploit this issue by providing a crafted image that, when used to overwrite an instance disk, exposes critical host files that should remain secure.
References
Timeline
Vulnerability published
Vulnerability Reserved