CVE-2013-2256: Openstack Nova
Medium severity, CVSS 6.0. EPSS: 1.8% chance of exploitation in the next 30 days.
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor id.
Affected products
- Openstack Nova: from 2013.1, before 2013.1.3 (fixed in 2013.1.3); version 2013.2 only
Published 2013-09-16. Last modified 2026-06-16.