OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nova | Jul 30, 2024 | Mar 22, 2013 |
| Suse | — | Upgrade openstack-nova-schedulerUpgrade openstack-nova-certUpgrade python-keystoneclient-docUpgrade openstack-nova-apiUpgrade python-glanceUpgrade python-keystoneclientUpgrade openstack-nova-networkUpgrade python-cinderclient-testUpgrade openstack-swift-testUpgrade openstack-novaUpgrade python-horizonUpgrade openstack-glance-docUpgrade python-keystoneUpgrade openstack-quickstartUpgrade openstack-quantum-testUpgrade openstack-keystone-docUpgrade openstack-quantumUpgrade python-cinderclient-docUpgrade openstack-nova-computeUpgrade python-keystoneclient-testUpgrade openstack-nova-novncproxyUpgrade openstack-dashboardUpgrade openstack-swift-containerUpgrade openstack-keystone-testUpgrade python-novaUpgrade openstack-cinder-volumeUpgrade openstack-keystoneUpgrade openstack-dashboard-testUpgrade openstack-swift-objectUpgrade openstack-cinder-schedulerUpgrade openstack-glance-testUpgrade openstack-nova-volumeUpgrade python-swiftUpgrade openstack-nova-objectstoreUpgrade python-quantumUpgrade openstack-cinder-docUpgrade openstack-quantum-docUpgrade python-cinderclientUpgrade openstack-swift-proxyUpgrade openstack-cinder-apiUpgrade openstack-swiftUpgrade python-cinderUpgrade python-django_openstack_authUpgrade openstack-nova-testUpgrade openstack-swift-accountUpgrade openstack-nova-docUpgrade openstack-cinder-testUpgrade openstack-nova-vncproxyUpgrade openstack-swift-docUpgrade openstack-glanceUpgrade openstack-cinder | Dec 12, 2013 | Mar 22, 2013 |
| Ubuntu | — | Upgrade python-nova | Nov 8, 2024 | Mar 22, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub