OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nova | Jul 30, 2024 | Oct 26, 2015 |
| Oracle Solaris | — | Upgrade cloud/openstack/horizon to version 0.2014.2.2-0.175.3.6.0.1.0 on Solaris 11.3Upgrade cloud/openstack/nova to version 0.2014.2.2-0.175.3.6.0.3.0 on Solaris 11.3Upgrade cloud/openstack/cinder to version 0.2014.2.2-0.175.3.6.0.1.0 on Solaris 11.3 | May 29, 2017 | Oct 26, 2015 |
| Ubuntu | — | Upgrade python-nova | Oct 11, 2017 | Oct 26, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub