{"id":"USN-5866-1","summary":"nova vulnerabilities","details":"It was discovered that Nova did not properly manage data logged into the\nlog file. An attacker with read access to the service's logs could exploit\nthis issue and may obtain sensitive information. This issue only affected\nUbuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)\n\nIt was discovered that Nova did not properly handle attaching and\nreattaching the encrypted volume. An attacker could possibly use this issue\nto perform a denial of service attack. This issue only affected Ubuntu\n16.04 ESM. (CVE-2017-18191)\n\nIt was discovered that Nova did not properly handle the updation of domain\nXML after live migration. An attacker could possibly use this issue to\ncorrupt the volume or perform a denial of service attack. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2020-17376)\n\nIt was discovered that Nova was not properly validating the URL passed to\nnoVNC. An attacker could possibly use this issue by providing malicious URL\nto the noVNC proxy to redirect to any desired URL. This issue only affected\nUbuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-3654)\n\nIt was discovered that Nova did not properly handle changes in the neutron\nport of vnic_type type. An authenticated user could possibly use this issue\nto perform a denial of service attack. This issue only affected Ubuntu\n20.04 LTS. (CVE-2022-37394)\n","modified":"2026-02-10T04:42:57Z","published":"2023-02-13T10:41:19Z","related":["UBUNTU-CVE-2015-9543","UBUNTU-CVE-2017-18191","UBUNTU-CVE-2020-17376","UBUNTU-CVE-2021-3654","UBUNTU-CVE-2022-37394"],"upstream":["CVE-2015-9543","CVE-2017-18191","CVE-2020-17376","CVE-2021-3654","CVE-2022-37394","UBUNTU-CVE-2015-9543","UBUNTU-CVE-2017-18191","UBUNTU-CVE-2020-17376","UBUNTU-CVE-2021-3654","UBUNTU-CVE-2022-37394"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5866-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-9543"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-18191"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-17376"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3654"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-37394"}],"affected":[{"package":{"name":"nova","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/nova@2:13.1.4-0ubuntu4.5+esm1?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:13.1.4-0ubuntu4.5+esm1"}]}],"versions":["2:12.0.0-0ubuntu2","2:13.0.0~b1-0ubuntu1","2:13.0.0~b2-0ubuntu1","2:13.0.0~b3-0ubuntu1","2:13.0.0~rc1-0ubuntu1","2:13.0.0~rc3-0ubuntu1","2:13.0.0-0ubuntu1","2:13.0.0-0ubuntu2","2:13.0.0-0ubuntu5","2:13.1.0-0ubuntu1","2:13.1.1-0ubuntu1","2:13.1.1-0ubuntu1.1","2:13.1.2-0ubuntu2","2:13.1.3-0ubuntu1","2:13.1.3-0ubuntu2","2:13.1.4-0ubuntu1","2:13.1.4-0ubuntu2","2:13.1.4-0ubuntu3","2:13.1.4-0ubuntu4.1","2:13.1.4-0ubuntu4.2","2:13.1.4-0ubuntu4.3","2:13.1.4-0ubuntu4.4","2:13.1.4-0ubuntu4.5"],"ecosystem_specific":{"binaries":[{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-ajax-console-proxy"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-api"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-api-metadata"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-api-os-compute"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-api-os-volume"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-cells"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-cert"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-common"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-kvm"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-libvirt"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-lxc"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-qemu"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-vmware"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-compute-xen"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-conductor"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-console"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-consoleauth"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-network"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-novncproxy"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-scheduler"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-serialproxy"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-spiceproxy"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-volume"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"nova-xvpvncproxy"},{"binary_version":"2:13.1.4-0ubuntu4.5+esm1","binary_name":"python-nova"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5866-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"id":"CVE-2015-9543","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2017-18191","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2021-3654","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}]}]}}},{"package":{"name":"nova","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/nova@2:17.0.13-0ubuntu5.3?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:17.0.13-0ubuntu5.3"}]}],"versions":["2:16.0.1-0ubuntu1","2:16.0.1-0ubuntu2","2:17.0.0~b1-0ubuntu1","2:17.0.0~b2-0ubuntu2","2:17.0.0~b3-0ubuntu3","2:17.0.0~b3-0ubuntu4","2:17.0.0~rc1-0ubuntu1","2:17.0.0~rc2-0ubuntu1","2:17.0.0~rc3-0ubuntu1","2:17.0.0-0ubuntu1","2:17.0.1-0ubuntu1","2:17.0.3-0ubuntu1","2:17.0.4-0ubuntu1","2:17.0.5-0ubuntu1","2:17.0.5-0ubuntu2","2:17.0.6-0ubuntu1","2:17.0.7-0ubuntu1","2:17.0.7-0ubuntu2","2:17.0.9-0ubuntu1","2:17.0.9-0ubuntu3","2:17.0.10-0ubuntu2","2:17.0.10-0ubuntu2.1","2:17.0.11-0ubuntu1","2:17.0.12-0ubuntu1","2:17.0.13-0ubuntu1","2:17.0.13-0ubuntu2","2:17.0.13-0ubuntu3","2:17.0.13-0ubuntu4","2:17.0.13-0ubuntu5","2:17.0.13-0ubuntu5.2"],"ecosystem_specific":{"binaries":[{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-ajax-console-proxy"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-api"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-api-metadata"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-api-os-compute"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-api-os-volume"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-cells"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-common"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-kvm"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-libvirt"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-lxc"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-qemu"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-vmware"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-compute-xen"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-conductor"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-console"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-consoleauth"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-network"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-novncproxy"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-placement-api"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-scheduler"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-serialproxy"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-spiceproxy"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-volume"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"nova-xvpvncproxy"},{"binary_version":"2:17.0.13-0ubuntu5.3","binary_name":"python-nova"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5866-1.json","cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"id":"CVE-2015-9543","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2020-17376","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"},{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2021-3654","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}]}]}}},{"package":{"name":"nova","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/nova@2:21.2.4-0ubuntu2.2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:21.2.4-0ubuntu2.2"}]}],"versions":["2:20.0.0-0ubuntu1","2:21.0.0~b1~git2019120415.45fb747c98-0ubuntu1","2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu2","2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu4","2:21.0.0~b2~git2020021008.1fcd74730d-0ubuntu5","2:21.0.0~b3~git2020041013.57ff308d6d-0ubuntu2","2:21.0.0-0ubuntu0.20.04.1","2:21.0.0-0ubuntu0.20.04.2","2:21.1.0-0ubuntu1","2:21.1.1-0ubuntu2","2:21.1.2-0ubuntu1","2:21.2.0-0ubuntu1","2:21.2.1-0ubuntu1","2:21.2.2-0ubuntu1","2:21.2.3-0ubuntu1","2:21.2.4-0ubuntu1","2:21.2.4-0ubuntu2","2:21.2.4-0ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-ajax-console-proxy"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-api"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-api-metadata"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-api-os-compute"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-api-os-volume"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-cells"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-common"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-kvm"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-libvirt"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-lxc"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-qemu"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-vmware"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-compute-xen"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-conductor"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-novncproxy"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-scheduler"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-serialproxy"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-spiceproxy"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"nova-volume"},{"binary_version":"2:21.2.4-0ubuntu2.2","binary_name":"python3-nova"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5866-1.json","cves_map":{"ecosystem":"Ubuntu:20.04:LTS","cves":[{"id":"CVE-2022-37394","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}]}}}],"schema_version":"1.7.3"}