Skip to content

OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service

Moderate severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Feb 13, 2023

Package

pip nova (pip)

Affected versions

< 2014.1.3

Patched versions

2014.1.3

Description

The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.

References

Published by the National Vulnerability Database Oct 6, 2014
Published to the GitHub Advisory Database May 14, 2022
Reviewed Feb 8, 2023
Last updated Feb 13, 2023

Severity

Moderate

EPSS score

0.666%
(80th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2014-3608

GHSA ID

GHSA-92hc-c226-32q7
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.