CVE-2014-0167Medium▾ SunlitOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.6%
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.
nova >= 2013.1.0, < 2013.2.4Upgrade to a patched release:
nova 2013.2.4Connected by shared product, vendor, weakness, or advisory.
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2015-0259MediumOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
CVE-2021-3654Medium· 6.1Open Redirect in CPython that affects users of OpenStack Nova
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service
CVE-2013-4179MediumOpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
CVE-2014-3608MediumOpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service