Access Restriction Bypass Affecting nova package, versions <2014.1.1-4


0.0
medium

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.13% (49th percentile)
Expand this section
NVD
5.3 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN11-NOVA-522079
  • published 19 Jun 2014
  • disclosed 19 Jun 2014

How to fix?

Upgrade Debian:11 nova to version 2014.1.1-4 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nova package and not the nova package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.