PT-2013-3422 · Openstack · Openstack Compute

Publicado

2013-03-22

·

Atualizado

2022-05-17

·

CVE-2013-1838

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1)
Description The issue allows remote authenticated users to cause a denial of service, resulting in resource exhaustion and failure to spawn new instances, by making a large number of calls to the addFixedIp function. This is due to the improper implementation of a quota for fixed IPs.
Recommendations For OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1), consider restricting access to the addFixedIp function to prevent excessive calls and mitigate the risk of resource exhaustion.

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1838
GHSA-63FQ-8FP9-VHWQ
PYSEC-2013-44
RHSA-2013:0709

Produtos afetados

Openstack Compute