CVE-2013-0326
Publication date 5 December 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
OpenStack nova base images permissions are world readable
Status
Package | Ubuntu Release | Status |
---|---|---|
nova | 14.04 LTS trusty | Not in release |
Notes
seth-arnold
/var/lib/nova/instances/_base/ apparently stores images with DAC permissions set to 0644. Deferred while waiting for upstream to address the issue -- I suspect the fix is simple, but the consequences may not be.
jdstrand
Ignoring. VMs are confined by AppArmor and are not able to read each other's files. Even if this were not the case, the files would be readable by the the libvirt-qemu:kvm user, so changing the permissions to 0640 would not help greatly. Therefore the protection would only be against other users on the system and a typical production Nova installation will not have these types of users or extra services. Furthermore, changing the permissions in a security update could be disruptive to production systems on upgrade. no upstream fix as of 2014-05-05
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 · Medium |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |