CVE-2013-2256

Openstack Nova < 2013.1.3 - Access Control

Title source: rule

Description

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.

Scores

EPSS 0.0047
EPSS Percentile 64.3%

Classification

CWE
CWE-264
Status draft

Affected Products (3)

openstack/nova < 2013.1.3
openstack/nova
pypi/nova < 2013.1.3PyPI

Timeline

Published Sep 16, 2013
Tracked Since Feb 18, 2026