OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/03/24/10 | third party advisory mailing list |
https://review.openstack.org/#/c/338929/ | third party advisory |
http://www.securityfocus.com/bid/77505 | vdb entry third party advisory |
https://bugs.launchpad.net/nova/+bug/1419577 | issue tracking vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1205313 | issue tracking vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2015/03/25/3 | third party advisory mailing list |