VulnerabilityModified
CVE-2011-4596
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or…
MEDIUM 6.0EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- openstack/nova
- Source
- secalert@redhat.com
References
- https://bugs.launchpad.net/nova/+bug/885167Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/894755Third Party Advisory
- https://github.com/openstack/nova/commit/76363226bd8533256f7795bba358d7f4b8a6c9e6Third Party Advisory
- https://github.com/openstack/nova/commit/ad3241929ea00569c74505ed002208ce360c667eThird Party Advisory
- https://lists.launchpad.net/openstack/msg06105.htmlThird Party Advisory
- https://bugs.launchpad.net/nova/+bug/885167Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/894755Third Party Advisory
- https://github.com/openstack/nova/commit/76363226bd8533256f7795bba358d7f4b8a6c9e6Third Party Advisory
- https://github.com/openstack/nova/commit/ad3241929ea00569c74505ed002208ce360c667eThird Party Advisory
- https://lists.launchpad.net/openstack/msg06105.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.