Описание
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 18.0.0 (включая) до 31.3.1 (исключая)Версия от 32.0.0 (включая) до 32.2.1 (исключая)Версия от 33.0.0 (включая) до 33.0.2 (исключая)
Одно из
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.00272
Низкий
5.4 Medium
CVSS3
8.5 High
CVSS3
Дефекты
CWE-669
Связанные уязвимости
CVSS3: 5.4
ubuntu
около 2 месяцев назад
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
CVSS3: 8.5
redhat
около 2 месяцев назад
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
CVSS3: 5.4
debian
около 2 месяцев назад
In OpenStack Nova before 33.0.2, the server create API does not strip ...
CVSS3: 5.4
github
около 2 месяцев назад
OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints
EPSS
Процентиль: 19%
0.00272
Низкий
5.4 Medium
CVSS3
8.5 High
CVSS3
Дефекты
CWE-669