{"id":"CVE-2013-7048","aliases":["GHSA-grp5-h379-j75x","PYSEC-2026-873"],"url":"https://o3.security/vulnerability/CVE-2013-7048","summary":"OpenStack Nova live snapshots use an insecure local directory","details":"OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.","published":"2014-01-23T21:55:04Z","modified":"2026-07-07T11:56:35.727047990Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"nova","fixedVersion":"12.0.0a0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0231.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2014/01/13/2"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/nova/+bug/1227027"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2014/01/13/2"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/nova/+bug/1227027"},{"type":"FIX","url":"https://bugs.launchpad.net/nova/+bug/1227027"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:35.727047990Z"}}