← Vulnerability feed

Vulnerability record · CVE-2013-7130 · published 6 February 2014

CVE-2013-7130: Openstack compute information exposure vulnerability

Openstack · Compute

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.

7.1 CVSS 2.0 High EPSS 2.4% · top 16.3% CWE-200 · Information exposure
7.1CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
26References
17 Jun 2026Last modified by NVD

Description

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.

AV:N/AC:M/Au:N/C:C/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-7130 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2013-0335Openstack essex insufficient session expiration vulnerabilityOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…EPSS 2.1%7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%6.8CVE-2015-1851Canonical ubuntu linux information exposure vulnerabilityOpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users t…EPSS 2.6%6.4CVE-2013-4497Openstack havana permissions and access controls vulnerabilityThe XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…EPSS 1.8%6.0CVE-2014-0162Openstack icehouse improper input validation vulnerabilityThe Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote …EPSS 2.0%6.0CVE-2014-0167Openstack compute permissions and access controls vulnerabilityThe Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R…EPSS 1.6%5.9CVE-2013-2255Openstack compute improper certificate validation vulnerabilityHTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…EPSS 0.97%5.0CVE-2013-6419Openstack havana information exposure vulnerabilityInteraction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2013-7130), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.