-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing RBAC enforcement in EC2 API security group operations. The patches add policy checks to three key methods in nova/api/ec2/cloud.py that handle security group management. These functions would appear in runtime profiles when processing EC2 API requests for security group modifications. The explicit addition of policy enforcement wrappers in the patches confirms these were the vulnerable entry points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nova | pip | >= 2013.1.0, < 2013.2.4 | 2013.2.4 |
Ongoing coverage of React2Shell