CVE-2012-3361: Openstack Diablo

Medium severity, CVSS 5.5. EPSS: 2.6% chance of exploitation in the next 30 days.

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

Affected products

Published 2012-07-22. Last modified 2026-06-16.