OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugs.launchpad.net/nova/+bug/1227027 | exploit third party advisory patch |
http://rhn.redhat.com/errata/RHSA-2014-0231.html | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2014/01/13/2 | third party advisory mailing list |