Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m674-hmx2-ffhq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 12.0.0a0

12.0.0a0

EPSS

Процентиль: 30%
0.00383
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

ubuntu
около 13 лет назад

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

redhat
около 13 лет назад

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

nvd
около 13 лет назад

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

debian
около 13 лет назад

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify t ...

EPSS

Процентиль: 30%
0.00383
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-770