Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2j5-7vgx-6xrx

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption

The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4

Пакеты

Наименование

cinder

pip
Затронутые версииВерсия исправления

< 7.0.2

7.0.2

Наименование

cinder

pip
Затронутые версииВерсия исправления

>= 8.0.0, < 9.0.0

9.0.0

Наименование

glance

pip
Затронутые версииВерсия исправления

< 14.0.0

14.0.0

Наименование

nova

pip
Затронутые версииВерсия исправления

< 12.0.4

12.0.4

EPSS

Процентиль: 87%
0.0359
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

CVSS3: 5.3
redhat
больше 10 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

CVSS3: 7.5
nvd
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.

CVSS3: 7.5
debian
больше 9 лет назад

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Gl ...

EPSS

Процентиль: 87%
0.0359
Низкий

7.5 High

CVSS3

Дефекты

CWE-400