Vulnerability Description
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Nova | <= 14.0.9 |
References
- http://www.securityfocus.com/bid/101950Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0241
- https://access.redhat.com/errata/RHSA-2018:0314
- https://access.redhat.com/errata/RHSA-2018:0369
- https://launchpad.net/bugs/1664931Issue Tracking
- https://security.openstack.org/ossa/OSSA-2017-005.htmlVendor Advisory
- https://www.debian.org/security/2017/dsa-4056
- http://www.securityfocus.com/bid/101950Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0241
- https://access.redhat.com/errata/RHSA-2018:0314
- https://access.redhat.com/errata/RHSA-2018:0369
- https://launchpad.net/bugs/1664931Issue Tracking
- https://security.openstack.org/ossa/OSSA-2017-005.htmlVendor Advisory
- https://www.debian.org/security/2017/dsa-4056
FAQ
What is CVE-2017-16239?
CVE-2017-16239 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filter...
How severe is CVE-2017-16239?
CVE-2017-16239 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16239?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Nova.