Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2654
Description:The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
Test IDs: 1.3.6.1.4.1.25623.1.0.841028   1.3.6.1.4.1.25623.1.0.71631   1.3.6.1.4.1.25623.1.0.864497  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2654
46808
http://secunia.com/advisories/46808
49439
http://secunia.com/advisories/49439
USN-1466-1
http://www.ubuntu.com/usn/USN-1466-1
[openstack] 20120606 [OSSA 2012-007] Security groups fail to be set correctly (CVE-2012-2654)
https://lists.launchpad.net/openstack/msg12883.html
https://bugs.launchpad.net/nova/+bug/985184
https://bugs.launchpad.net/nova/+bug/985184
https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978
https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978
https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654
https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654
https://review.openstack.org/#/c/8239/
https://review.openstack.org/#/c/8239/
nova-security-group-sec-bypass(76110)
https://exchange.xforce.ibmcloud.com/vulnerabilities/76110




© 1998-2025 E-Soft Inc. All rights reserved.