CVE-2013-2030: Openstack Compute
Low severity, CVSS 2.1. EPSS: 0.2% chance of exploitation in the next 30 days.
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
Affected products
- Openstack Compute: version 2013.1 only; version 2013.1.1 only; version 2013.1.2 only; version 2013.1.3 only
- Openstack Folsom: affected versions not specified
- Openstack Grizzly: version 2013.1 only
- Openstack Havana: version havana-1 only; version havana-2 only; version havana-3 only
Published 2013-12-27. Last modified 2026-06-16.