← Back

CVE-2013-4497

nvd nist
Published: Nov 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

Affected (5)

3 products
Havana
Grizzly
Folsom
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Openstack
Up to havana-3
Version havana-1
Version havana-2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Related CWEs

References (8)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.