CVE-2015-2687

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
09/08/2017
Last modified:
20/04/2025

Description

OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:compute:2013.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.2.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.2.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.2.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2013.2.4:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1.4:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.1.5:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.2.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.2.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:compute:2014.2.3:*:*:*:*:*:*:*