PT-2013-3422 · Openstack · Openstack Compute
Published
2013-03-22
·
Updated
2022-05-17
·
CVE-2013-1838
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1)
Description
The issue allows remote authenticated users to cause a denial of service, resulting in resource exhaustion and failure to spawn new instances, by making a large number of calls to the
addFixedIp function. This is due to the improper implementation of a quota for fixed IPs.Recommendations
For OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1), consider restricting access to the
addFixedIp function to prevent excessive calls and mitigate the risk of resource exhaustion.Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Compute