---
id: CVE-2013-2256
aliases:
  - GHSA-5mj6-643f-2g85
  - PYSEC-2026-866
title: >-
  OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive
  information
summary: >-
  OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive
  information
severity: medium
vendor: nova
product: nova
ecosystem: pip
affected:
  - nova < 2013.1.3
patched:
  - nova 2013.1.3
published: '2022-05-14'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:20.104369343Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5mj6-643f-2g85'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-2256'
  - url: 'https://access.redhat.com/errata/RHSA-2013:1199'
  - url: 'https://access.redhat.com/security/cve/CVE-2013-2256'
  - url: 'https://bugs.launchpad.net/nova/+bug/1194093'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=993340'
  - url: 'https://opendev.org/openstack/nova'
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-1199.html'
  - url: 'http://seclists.org/oss-sec/2013/q3/281'
tags:
  - osv
  - pip
epss: 0.01844
epssPercentile: 0.77765
ingestedAt: '2026-07-08T18:25:46.035Z'
---

## Overview

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.

## Affected packages

- `nova < 2013.1.3`

## Remediation

Upgrade to a patched release:

- `nova 2013.1.3`
