CVE-2014-0134

OpenStack Compute (Nova) <2013.2.3-2014.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/nova/+bug/1221190
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2247-1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/03/27/6

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Details

CWE
CWE-200
Status published
Products (4)
openstack/compute 2013.2
openstack/compute 2013.2.1
openstack/compute 2013.2.2
pypi/nova 0 - 12.0.0a0PyPI
Published May 08, 2014
Tracked Since Feb 18, 2026