CVE-2011-4596
Last modified
CVE-2011-4596 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.. EPSS estimates a 1.94% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball or (2) manifest.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Nova | >= 2011.3, < 2011.3.1 |
References
- https://bugs.launchpad.net/nova/+bug/885167Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/894755Third Party Advisory
- https://lists.launchpad.net/openstack/msg06105.htmlThird Party Advisory
- https://bugs.launchpad.net/nova/+bug/885167Third Party Advisory
- https://bugs.launchpad.net/nova/+bug/894755Third Party Advisory
- https://lists.launchpad.net/openstack/msg06105.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4596?
How severe is CVE-2011-4596?
How do I fix CVE-2011-4596?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4590The web services implementation in Moodle 2.0.x before 2.0.6…
- CVE-2011-4591Cross-site scripting (XSS) vulnerability in the print_object…
- CVE-2011-4592The command-line cron implementation in Moodle 2.0.x before …
- CVE-2011-4593Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x be…
- CVE-2011-4594The __sys_sendmsg function in net/socket.c in the Linux kern…5.5
- CVE-2011-4595Pretty-Link WordPress plugin 1.5.2 has XSS6.1
- CVE-2011-4597The SIP over UDP implementation in Asterisk Open Source 1.4.…
- CVE-2011-4598The handle_request_info function in channels/chan_sip.c in A…
- CVE-2011-4599Stack-based buffer overflow in the _canonicalize function in…
- CVE-2011-4600The networkReloadIptablesRules function in network/bridge_dr…
- CVE-2011-4601family_feedbag.c in the oscar protocol plugin in libpurple i…
- CVE-2011-4602The XMPP protocol plugin in libpurple in Pidgin before 2.10.…
Are you affected by CVE-2011-4596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
