CVE-2013-4497 describes a security vulnerability in OpenStack Compute (Nova) Folsom, Grizzly, and Havana, where the XenAPI backend fails to properly apply security groups during image resizing or live migration. This medium-severity vulnerability (CVSS 6.4) allows remote attackers to bypass intended network restrictions, potentially leading to unauthorized access to virtual machines. While the vulnerability has a low EPSS score and no known public exploits or community discussion, it represents a clear security bypass that could be leveraged by an attacker with network access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= havana-3CPE matchmatch criteria | cpe:2.3:a:openstack:havana:*:*:*:*:*:*:*:* | ||
havana-1CPE matchmatch criteria | cpe:2.3:a:openstack:havana:havana-1:*:*:*:*:*:*:* | ||
havana-2CPE matchmatch criteria | cpe:2.3:a:openstack:havana:havana-2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.