VDB
KO

PYSEC-2013-43

Details

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / nova
Introduced in: 0 Fixed in: 12.0.0a0
Fix pip install --upgrade 'nova>=12.0.0a0'

References