CVE-2013-2030

OpenStack Nova Folsom, Grizzly, Havana - Server Spoofing via Insecure Temporary Directory

Title source: llm
STIX 2.1

Description

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/09/2
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.html
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.openstack.org/pipermail/openstack-announce/2013-May/000098.html
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/nova/+bug/1174608
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=958285

Scores

EPSS 0.0003
EPSS Percentile 10.7%

Details

CWE
CWE-264
Status published
Products (10)
openstack/compute 2013.1
openstack/compute 2013.1.1
openstack/compute 2013.1.2
openstack/compute 2013.1.3
openstack/folsom
openstack/grizzly 2013.1
openstack/havana havana-1
openstack/havana havana-2
openstack/havana havana-3
pypi/python-keystoneclient 0 - 0.2.4PyPI
Published Dec 27, 2013
Tracked Since Feb 18, 2026