Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. nova
  4. ›
  5. CVE-2015-0259

CVE-2015-0259: Insufficient Verification of Data Authenticity

May 14, 2022 (updated February 8, 2023)

It was discovered that the OpenStack Compute (nova) console websocket does not correctly verify the origin header. An attacker could use this flaw to conduct a cross-site websocket hijack attack. Note that only Compute setups with VNC or SPICE enabled were affected by this flaw.

References

  • lists.openstack.org/pipermail/openstack-announce/2015-March/000341.html
  • rhn.redhat.com/errata/RHSA-2015-0790.html
  • rhn.redhat.com/errata/RHSA-2015-0843.html
  • rhn.redhat.com/errata/RHSA-2015-0844.html
  • access.redhat.com/errata/RHSA-2015:0790
  • access.redhat.com/errata/RHSA-2015:0843
  • access.redhat.com/errata/RHSA-2015:0844
  • access.redhat.com/security/cve/CVE-2015-0259
  • bugs.launchpad.net/nova/+bug/1409142
  • bugzilla.redhat.com/show_bug.cgi?id=1190112
  • github.com/advisories/GHSA-x8xr-rm9r-7mvf
  • nvd.nist.gov/vuln/detail/CVE-2015-0259

Code Behaviors & Features

Detect and mitigate CVE-2015-0259 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2014.1.4, all versions starting from 2014.2.0 before 2014.2.3

Fixed versions

  • 2014.1.4
  • 2014.2.3

Solution

Upgrade to versions 2014.1.4, 2014.2.3 or above.

Impact 5.1 MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Learn more about CVSS

Weakness

  • CWE-345: Insufficient Verification of Data Authenticity

Source file

pypi/nova/CVE-2015-0259.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:31 +0000.