CVE-2012-2654

Source
https://cve.org/CVERecord?id=CVE-2012-2654
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-2654.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-2654
Aliases
Downstream
Published
2012-06-21T15:55:12Z
Modified
2025-08-09T19:01:28Z
Summary
[none]
Details

The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.

References

Affected packages