Vulnerable Systems:
*OpenStack Compute (Nova) 2012.1 and prior
OpenStack Compute (Nova) contains a flaw in the 'create' method. The issue is triggered when the 'block_device_mapping' parameter fails to properly verify volume IDs when using the 'Boot From Volume' functionality. This may allow a local authenticated attacker to bypass access restrictions and gain access to the volume.