VDB
Sign up
—

PYSEC-2026-881

OpenStack Nova Multiple directory traversal vulnerabilities

Quick fix

PYSEC-2026-881 — nova: upgrade to the fixed version with the command below.

pip install --upgrade 'nova>=12.0.0a0'

Details

Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nova
Introduced in: 0Fixed in: 12.0.0a0
Fixpip install --upgrade 'nova>=12.0.0a0'

References