CVE-2012-2654
OpenStack Compute (Nova) Improper Input Validation
EPSS 2.6%
描述
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
如何修補 CVE-2012-2654
要修補 CVE-2012-2654,請將受影響套件升級到下列已修補版本。
- Debian/nova—升級至 2012.1-6 或更新版本
- PyPI/nova—升級至 12.0.0a0 或更新版本
- PyPI/nova—升級至 9f9e9da777161426a6f8cb4314b78e09beac2978 或更新版本
CVE-2012-2654 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2012.1-6
- from 0, < 12.0.0a0
- from 0, < 9f9e9da777161426a6f8cb4314b78e09beac2978, < ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654 | from 0