GHSA-w429-xc55-hc48 · Severity: low · Ecosystem: pip — OpenStack Nova host data leak to vm instance in rescue mode
The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.
Conclusion & alert: CVE-2014-0134 is rated Moderate Risk (40/100): CVSS Low severity, with medium exploitation likelihood (EPSS 1.49%). Core evidence: EPSS rose +1.29% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.20% | 1.49% | +1.29% |
| 2 | 2025-03-22 | 0.32% | 0.20% | -0.12% |
| 3 | 2025-03-17 | — | 0.32% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-w429-xc55-hc48 · Severity: low · Ecosystem: pip — OpenStack Nova host data leak to vm instance in rescue mode
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2014-0134 not yet assigned priority: Debian including 1 source packages (nova), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2014-0134 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2014-0134 |
ubuntu
|
medium | CVE-2014-0134 medium priority: Ubuntu including 1 source packages (nova), 6 status rows across 6 suites (lucid, precise, quantal, saucy, trusty, upstream): DNE 2, not-affected 2, released 2. | https://ubuntu.com/security/CVE-2014-0134 |