CVE-2015-0259

Openstack Nova < 2014.1.4 - Data Authenticity Bypass

Title source: rule

Description

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

Scores

EPSS 0.0021
EPSS Percentile 42.4%

Classification

CWE
CWE-345
Status draft

Affected Products (4)

openstack/nova < 2014.1.4
openstack/nova
openstack/nova
pypi/nova < 2014.1.4PyPI

Timeline

Published Apr 01, 2015
Tracked Since Feb 18, 2026