CVE-2011-4596

Openstack Nova < 2011.3.1 - Path Traversal

Title source: rule

Description

Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.

Scores

EPSS 0.0054
EPSS Percentile 67.3%

Classification

CWE
CWE-22
Status draft

Affected Products (2)

openstack/nova < 2011.3.1
pypi/nova < 12.0.0a0PyPI

Timeline

Published Dec 23, 2011
Tracked Since Feb 18, 2026