PT-2014-5416 · Openstack+1 · Openstack Compute+1

Garth Mollett

·

Published

2014-10-06

·

Updated

2023-02-13

·

CVE-2014-3608

CVSS v2.0

2.7

Low

VectorAV:A/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions prior to 2014.1.3
Description The issue allows remote authenticated users to bypass the quota limit and cause a denial of service by consuming resources. This is achieved by putting a virtual machine into the rescue state, suspending it, which results in an ERROR state, and then deleting the image. The problem exists due to an incomplete fix for a previous issue.
Recommendations For versions prior to 2014.1.3, update to version 2014.1.3 or later to resolve the issue.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2014-3608
GHSA-92HC-C226-32Q7
RHSA-2014:1781
RHSA-2014:1782
SUSE-SU-2015:0324-1
USN-2407-1

Affected Products

Openstack Compute
Ubuntu