OpenStack Nova Multiple directory traversal vulnerabilities
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Description
Published by the National Vulnerability Database
Dec 23, 2011
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
May 14, 2024
Last updated
May 14, 2024
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
References