VYPR
Moderate severityNVD Advisory· Published Sep 16, 2013· Updated Apr 29, 2026

CVE-2013-2256

CVE-2013-2256

Description

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
novaPyPI
< 2013.1.32013.1.3

Affected products

2
  • OpenStack/Nova2 versions
    cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*range: >=2013.1,<2013.1.3
    • cpe:2.3:a:openstack:nova:2013.2:milestone1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.