ossa/ossa/OSSA-2014-009.yaml

60 lines
1.4 KiB
YAML

date: 2014-03-27
id: OSSA-2014-009
title: 'Nova host data leak to vm instance in rescue mode'
description: 'Stanislaw Pitucha from Hewlett Packard reported a vulnerability in the
Nova instance rescue mode. By overwriting the disk inside an instance with a malicious
image and switching the instance to rescue mode, an authenticated user would be
able to leak an arbitrary file from the compute host to the virtual instance. Note
that the host file must be readable by the libvirt/kvm context to be exposed. Only
setups using libvirt to spawn instance, and having "use_cow_images = False" in Nova
configuration are affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-March/000213.html
affected-products:
- product: nova
version: 2013.2 versions up to 2013.2.2
vulnerabilities:
- cve-id: CVE-2014-0134
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 3.5
detail: AV:N/AC:M/Au:S/C:P/I:N/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Stanislaw Pitucha'
affiliation: HP
reported:
- CVE-2014-0134
issues:
links:
- https://launchpad.net/bugs/1221190
type: launchpad
reviews:
icehouse:
- https://review.openstack.org/#/c/82841
havana:
- https://review.openstack.org/#/c/82840
type: gerrit