CVE-2015-0259
Openstack Nova < 2014.1.4 - Data Authenticity Bypass
Title source: ruleDescription
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
References (5)
Scores
EPSS
0.0021
EPSS Percentile
42.4%
Classification
CWE
CWE-345
Status
draft
Affected Products (4)
openstack/nova
< 2014.1.4
openstack/nova
openstack/nova
pypi/nova
< 2014.1.4PyPI
Timeline
Published
Apr 01, 2015
Tracked Since
Feb 18, 2026