VDB
Sign up

PYSEC-2012-38

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2012-38 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=b0feaffdb2b1c51182b8dce41b367f3449af5dd9'

Details

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: b0feaffdb2b1c51182b8dce41b367f3449af5dd9
Fixpip install --upgrade 'nova>=b0feaffdb2b1c51182b8dce41b367f3449af5dd9'

References