CVE-2015-0259
01.04.2015, 14:59
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | nova | 2014.1 ≤ 𝑥 < 2014.1.4 |
openstack | nova | 2014.2 ≤ 𝑥 < 2014.2.3 |
openstack | nova | 2015.1.0:milestone1 |
openstack | nova | 2015.1.0:milestone2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References