Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:14427
HistoryMay 02, 2019 - 4:52 a.m.

Authorization Bypass

2019-05-0204:52:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

75.0%

openstack-nova is vulnerable to authorization bypass. It was found that the boot-from-volume feature in nova-volume did not correctly validate if the user attempting to boot an image was permitted to do so. An authenticated user could use this flaw to bypass intended restrictions, allowing them to boot images they would otherwise not have access to, exposing data stored in other users’ images. This issue does not affect configurations using the Cinder block storage mechanism, which is the default in Red Hat OpenStack.