- Description
- The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.
- Source
- secalert@redhat.com
- NVD status
- Deferred
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:N/A:P
- nvd@nist.gov
- CWE-399
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFD62B8C-D52F-4A31-ABDF-9390182BA803",
"versionEndExcluding": "2013.1.5",
"versionStartIncluding": "2013.1"
},
{
"criteria": "cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B2A2CFC-2233-4868-8508-6C513B201DA5",
"versionEndExcluding": "2013.2.2",
"versionStartIncluding": "2013.2"
},
{
"criteria": "cpe:2.3:a:openstack:nova:2014.1:milestone1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB6BAFED-3BC9-4B5E-890C-8AA14666E28D"
}
],
"operator": "OR"
}
]
}
]