Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq76-rxx3-4r4r

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

OpenStack Nova DoS by rebuilding the same instance with a new image multiple times

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 16.0.4

16.0.4

EPSS

Процентиль: 74%
0.00841
Низкий

8.6 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 8 лет назад

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

CVSS3: 5.3
redhat
около 8 лет назад

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

CVSS3: 8.6
nvd
около 8 лет назад

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

CVSS3: 8.6
debian
около 8 лет назад

An issue was discovered in the default FilterScheduler in OpenStack No ...

EPSS

Процентиль: 74%
0.00841
Низкий

8.6 High

CVSS3

Дефекты

CWE-400