CVE-2013-0335
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- EPSS probability
- 1.04%
- CWE
- CWE-613
- Published
- 2013-03-22
- Last modified
- 2026-07-31
Affected products
- n/a n/a
- Red Hat OpenStack Folsom for RHEL 6
Weakness type
Related vulnerabilities
- CVE-2025-59841 — FlagForgeCTF's Improper Session Handling Allows Access After Logout
- CVE-2026-1435 — Incorrect management of session invalidation vulnerability in Graylog Web Interface
- CVE-2024-13996 — Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
- CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2026-34572 — CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
- CVE-2025-54592 — FreshRSS has Incomplete Session Termination on Logout
- CVE-2026-26342 — Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration
- CVE-2026-24894 — FrankenPHP leaks session data between requests in worker mode