Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Nova 安全绕过漏洞
Vulnerability Description
OpenStack Compute(Nova)是用Python编写的云计算构造控制器,属于laaS系统的一部分。 OpenStack Compute (Nova) Grizzly,Folsom (2012.2),Essex (2012.1)中存在漏洞。通过对删除绑定相同VNC端口的VM使用VNC令牌,远程认证攻击者利用该漏洞在伺机情况下获得访问到VM的权限。
CVSS Information
N/A
Vulnerability Type
N/A