PT-2013-3422 · Openstack · Openstack Compute
Publicado
2013-03-22
·
Atualizado
2022-05-17
·
CVE-2013-1838
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1)
Description
The issue allows remote authenticated users to cause a denial of service, resulting in resource exhaustion and failure to spawn new instances, by making a large number of calls to the
addFixedIp function. This is due to the improper implementation of a quota for fixed IPs.Recommendations
For OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1), consider restricting access to the
addFixedIp function to prevent excessive calls and mitigate the risk of resource exhaustion.Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openstack Compute