Access Restriction Bypass Affecting nova package, versions [,14.0.10)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (61st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NOVA-2371932
  • published26 Jan 2022
  • disclosed14 Nov 2017
  • creditUnknown

Introduced: 14 Nov 2017

CVE-2017-16239  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade nova to version 14.0.10 or higher.

Overview

Affected versions of this package are vulnerable to Access Restriction Bypass. In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.

CVSS Scores

version 3.1