---
id: CVE-2013-4497
aliases:
  - GHSA-27q4-38qf-m25h
  - PYSEC-2026-859
title: OpenStack Compute Nova Improper Access Control
summary: OpenStack Compute Nova Improper Access Control
severity: medium
vendor: nova
product: nova
ecosystem: pip
affected:
  - nova < 12.0.0a0
patched:
  - nova 12.0.0a0
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-27q4-38qf-m25h'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-4497'
  - url: >-
      https://github.com/openstack/nova/commit/01de658210fd65171bfbf5450c93673b5ce0bd9e
  - url: >-
      https://github.com/openstack/nova/commit/5cced7a6dd32d231c606e25dbf762d199bf9cca7
  - url: >-
      https://github.com/openstack/nova/commit/ba0d007fb78bd1182c3c0b808dbd7ccc84640e80
  - url: >-
      https://github.com/openstack/nova/commit/df2ea2e3acdede21b40d47b7adbeac04213d031b
  - url: 'https://bugs.launchpad.net/nova/+bug/1073306'
  - url: 'https://bugs.launchpad.net/nova/+bug/1202266'
  - url: 'https://github.com/openstack/nova'
  - url: 'http://www.openwall.com/lists/oss-security/2013/11/03/2'
  - url: 'http://www.openwall.com/lists/oss-security/2013/11/03/3'
tags:
  - osv
  - pip
epss: 0.01823
epssPercentile: 0.77514
ingestedAt: '2026-07-08T18:25:44.175Z'
---

## Overview

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

## Affected packages

- `nova < 12.0.0a0`

## Remediation

Upgrade to a patched release:

- `nova 12.0.0a0`
