PT-2013-4892 · Openstack · Openstack Compute
Vishvananda
+1
·
Published
2013-10-29
·
Updated
2022-05-14
·
CVE-2013-4185
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Compute (Nova) versions before 2013.1.3
OpenStack Compute (Nova) Havana versions before havana-3
Description
The issue does not properly handle network source security group policy updates, allowing remote authenticated users to cause a denial of service via a large number of server-creation operations. This triggers a large number of update requests, consuming nova-network resources.
Recommendations
For OpenStack Compute (Nova) versions before 2013.1.3, update to version 2013.1.3 or later to resolve the issue.
For OpenStack Compute (Nova) Havana versions before havana-3, update to havana-3 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Compute