PT-2014-4786 · Vmware+1 · Vmware+1
Jaroslav Henner
+1
·
Publicado
2014-03-25
·
Atualizado
2022-05-17
·
CVE-2014-2573
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions 2013.2 through 2013.2.2
Description
The issue allows remote authenticated users to bypass the quota limit and cause a denial of service by requesting a VM be put into rescue and then deleting the image, due to the VMWare driver not properly putting VMs into RESCUE status.
Recommendations
For OpenStack Compute (Nova) versions 2013.2 through 2013.2.2, consider restricting access to the VM rescue functionality to prevent unauthorized users from exploiting this issue. As a temporary workaround, consider implementing additional quota checks to limit resource consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openstack Compute
Vmware