← Vulnerability feed

Vulnerability record · CVE-2013-6419 · published 7 January 2014

CVE-2013-6419: Openstack havana information exposure vulnerability

Openstack · Havana

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

5.0 CVSS 2.0 Medium EPSS 1.9% · top 21.7% CWE-200 · Information exposure
5.0CVSS 2.0 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6419 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%7.1CVE-2013-7130Openstack compute information exposure vulnerabilityThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…EPSS 2.4%6.4CVE-2013-4497Openstack havana permissions and access controls vulnerabilityThe XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…EPSS 1.8%4.3CVE-2013-4179Openstack havana memory buffer overflow vulnerabilityThe security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a den…EPSS 2.7%4.0CVE-2013-4155Openstack folsom memory buffer overflow vulnerabilityOpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumpt…EPSS 1.7%3.3CVE-2013-4477Openstack grizzly permissions and access controls vulnerabilityThe LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds t…EPSS 0.45%2.1CVE-2013-4463Openstack folsom vulnerabilityOpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a …EPSS 0.37%2.1CVE-2013-2030Openstack compute permissions and access controls vulnerabilitykeystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2013-6419), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.