CVE-2013-6419

medium
Published 2022-05-17 · Modified 2026-04-29
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-6419

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2013/12/11/8

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2013.2.1-1
debian debianbullseyefixed2013.2.1-1
debian debianforkyfixed2013.2.1-1
debian debiansidfixed2013.2.1-1
debian debiantrixiefixed2013.2.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPInova<12.0.0a012.0.0a0

Application impact

VendorProductVersionsFixed
openstackhavana{"endIncluding":"havana-1"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.