PT-2011-5002 · Openstack · Openstack Nova

·

CVE-2011-4596

·

Publicado

2011-12-23

·

Atualizado

2026-07-06

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Nova versions prior to 2011.3.1
Description The issue allows remote authenticated users to overwrite arbitrary files via a crafted tarball or manifest when the EC2 API and the S3/RegisterImage image-registration method are enabled.
Recommendations For versions prior to 2011.3.1, update to version 2011.3.1 or later to resolve the issue.

Correção

DoS

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4596
GHSA-QR62-R9XC-R2GJ
PYSEC-2026-881

Produtos afetados

Openstack Nova