World-writable and world-readable permissions in OpenStack Compute (Nova) allow unauthorized access to live snapshots

World-writable and world-readable permissions in OpenStack Compute (Nova) allow unauthorized access to live snapshots

CVE-2013-7048 · LOW Severity

AV:L/AC:M/AU:N/C:P/I:P/A:N

OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.

Learn more about our User Device Pen Test.