CVE-2013-4497: Openstack Folsom
Medium severity, CVSS 6.4. EPSS: 1.8% chance of exploitation in the next 30 days.
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.
Affected products
- Openstack Folsom: affected versions not specified
- Openstack Grizzly: affected versions not specified
- Openstack Havana: up to and including havana-3; version havana-1 only; version havana-2 only
Published 2013-11-05. Last modified 2026-06-16.