Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11195
HistoryJan 15, 2019 - 8:58 a.m.

Information Disclosure

2019-01-1508:58:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

62.0%

openstack-nova is vulnerable to information disclosure attacks. The vulnerability exists as OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.