UNKNOWN PyPI

OpenStack Nova live snapshots use an insecure local directory

GHSA-grp5-h379-j75x · CVE-2013-7048 · PYSEC-2026-873

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.

Ready to move

Start Securing

Free, no credit card | First findings in minutes