Lucene search

K
githubGitHub Advisory DatabaseGHSA-HQ3F-9GF7-73R8
HistoryMay 17, 2022 - 1:46 a.m.

Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules

2022-05-1701:46:41
GitHub Advisory Database
github.com
6
openstack
compute
nova
denial of service
network request
large number
iptables rules
folsom
2012.1
2011.3
security group rules
remote authenticated users
cpu consumption
hard drive consumption

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.013

Percentile

85.9%

Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.

Affected configurations

Vulners
Node
novanovaRange<12.0.0a0

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.013

Percentile

85.9%