CVE-2013-7130 describes a vulnerability in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, specifically within the libvirt driver's i_create_images_and_backing method during KVM live block migration. This flaw allows an attacker to access snapshot root disk contents of other users' virtual machines via ephemeral storage. With a CVSS score of 7.1, this vulnerability is considered high severity due to its network-based attack vector and high confidentiality impact, though it requires medium attack complexity. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2012.2CPE matchmatch criteria | cpe:2.3:a:openstack:compute:2012.2:*:*:*:*:*:*:* | ||
2013.1CPE matchmatch criteria | cpe:2.3:a:openstack:compute:2013.1:*:*:*:*:*:*:* | ||
2013.1.1CPE matchmatch criteria | cpe:2.3:a:openstack:compute:2013.1.1:*:*:*:*:*:*:* | ||
2013.1.2CPE matchmatch criteria | cpe:2.3:a:openstack:compute:2013.1.2:*:*:*:*:*:*:* | ||
2013.1.3CPE matchmatch criteria | cpe:2.3:a:openstack:compute:2013.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.