CVE-2015-0259Medium▾ SunlitOpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.1%
1.1% → 1.1%
Last analysed / modified upstream
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
nova < 2014.1.4nova >= 2014.2.0, < 2014.2.3Upgrade to a patched release:
nova 2014.1.4nova 2014.2.3Connected by shared product, vendor, weakness, or advisory.
CVE-2014-3708MediumOpenStack Compute (Nova) Denial of Service vulnerability
CVE-2014-8333MediumOpenStack Nova VMware instance leak potentially leading to compute DoS
CVE-2014-3517MediumOpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2021-3654Medium· 6.1Open Redirect in CPython that affects users of OpenStack Nova
CVE-2014-0167MediumOpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
CVE-2015-3280MediumOpenStack Compute (nova) allows remote authenticated users to cause a denial of service