Skip to content

Arbitrary file overwrite in OpenStack Nova

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Dec 21, 2023

Package

pip nova (pip)

Affected versions

< 12.0.0

Patched versions

12.0.0

Description

virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by root. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3361.

References

Published by the National Vulnerability Database Aug 20, 2012
Published to the GitHub Advisory Database May 17, 2022
Reviewed Feb 14, 2023
Last updated Dec 21, 2023

Severity

Moderate

Weaknesses

No CWEs

CVE ID

CVE-2012-3447

GHSA ID

GHSA-xc4g-7vw8-924h

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.