CVE-2011-4596
OpenStack Nova Multiple directory traversal vulnerabilities
EPSS 0.54%
Description
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
How to fix CVE-2011-4596
To remediate CVE-2011-4596, upgrade the affected package to a fixed version below.
- Debian/nova—upgrade to 2012.1~e1-4 or later
- PyPI/nova—upgrade to 12.0.0a0 or later
Is CVE-2011-4596 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2012.1~e1-4
- from 0, < 12.0.0a0