OSSA-2013-001: Boot from volume allows access to random volumes

OSSA-2013-001: Boot from volume allows access to random volumes

Date:January 29, 2013
CVE:CVE-2013-0208

Affects

  • Nova: Essex, Folsom

Description

Phil Day from HP reported a vulnerability in volume attachment in nova-volume, affecting the boot-from-volume feature. By passing a specific volume ID, an authenticated user may be able to boot from a volume he doesn’t own, potentially resulting in full access to that 3rd-party volume contents. Folsom setups making use of Cinder are not affected.

Credits

  • Phil Day from HP (CVE-2013-0208)
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.