Lucene search

K
cve[email protected]CVE-2012-3360
HistoryJul 22, 2012 - 4:55 p.m.

CVE-2012-3360

2012-07-2216:55:45
CWE-22
web.nvd.nist.gov
33
4
openstack compute
nova
folsom
essex
cve-2012-3360
nvd
security
vulnerability
directory traversal
remote code execution

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.0%

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a … (dot dot) in the path attribute of a file element.

Affected configurations

NVD
Node
openstackessexMatch2012.1
OR
openstackfolsomMatch2012.2

Social References

More

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.0%