CVE-2015-0259

CVSS V2 Medium 5.1 CVSS V3 None
Description
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.
Overview
  • CVE ID
  • CVE-2015-0259
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2015-04-01T14:59:01
  • Last Modified Date
  • 2023-02-13T00:46:05
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 1 OR 2014.1 2014.1.4
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* 1 OR 2014.2 2014.2.3
cpe:2.3:a:openstack:nova:2015.1.0:milestone1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openstack:nova:2015.1.0:milestone2:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:H/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • HIGH
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5.1
  • Severity
  • MEDIUM
  • Exploitability Score
  • 4.9
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 17:52:26 Added to TrackCVE
2022-12-02 04:07:50 2015-04-01T14:59Z 2015-04-01T14:59:01 CVE Published Date updated
2022-12-02 04:07:50 2018-11-16T15:07:47 CVE Modified Date updated
2022-12-02 04:07:50 Analyzed Vulnerability Status updated
2023-02-02 21:04:58 2023-02-02T20:20:02 CVE Modified Date updated
2023-02-02 21:04:58 Analyzed Modified Vulnerability Status updated
2023-02-02 21:04:59 OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage. It was discovered that the OpenStack Compute (nova) console websocket did not correctly verify the origin header. An attacker could use this flaw to conduct a cross-site websocket hijack attack. Note that only Compute setups with VNC or SPICE enabled were affected by this flaw. Description updated
2023-02-02 21:05:05 References updated
2023-02-13 01:05:53 2023-02-13T00:46:05 CVE Modified Date updated
2023-02-13 01:05:53 It was discovered that the OpenStack Compute (nova) console websocket did not correctly verify the origin header. An attacker could use this flaw to conduct a cross-site websocket hijack attack. Note that only Compute setups with VNC or SPICE enabled were affected by this flaw. OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage. Description updated