PT-2013-3422 · Openstack · Openstack Compute

Published

2013-03-22

·

Updated

2022-05-17

·

CVE-2013-1838

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1)
Description The issue allows remote authenticated users to cause a denial of service, resulting in resource exhaustion and failure to spawn new instances, by making a large number of calls to the addFixedIp function. This is due to the improper implementation of a quota for fixed IPs.
Recommendations For OpenStack Compute (Nova) versions Grizzly, Folsom (2012.2), Essex (2012.1), consider restricting access to the addFixedIp function to prevent excessive calls and mitigate the risk of resource exhaustion.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1838
GHSA-63FQ-8FP9-VHWQ
PYSEC-2013-44
RHSA-2013:0709

Affected Products

Openstack Compute