CVE-2012-2101
published 2012-06-07CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.48%
71.1th percentile
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2012.1-2 (bookworm) | nova 2012.1-2 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2012.1-2 | 2012.1-2 |
| openstack | nova | >= 0 < 2012.1-2 | 2012.1-2 |
| openstack | nova | >= 0 < 2012.1-2 | 2012.1-2 |
| openstack | nova | >= 0 < 2012.1-2 | 2012.1-2 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2012-05-03
CVE-2012-2101 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to crash the system under certain conditions.
Dan Prince discovered that Nova did not enforce quotas for security groups
and rules added to security groups. An authenticated user could exploit
this to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2101: nova - Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of...
vendor_debian·2012·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101: nova - Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of...
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Scope: local
bookworm: resolved (fixed in 2012.1-2)
bullseye: resolved (fixed in 2012.1-2)
forky: resolved (fixed in 2012.1-2)
sid: resolved (fixed in 2012.1-2)
trixie: resolved (fixed in 2012.1-2)
GHSA
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
ghsa·2022-05-17
CVE-2012-2101 [LOW] Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
OSV
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
osv·2022-05-17
CVE-2012-2101 [LOW] Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
OSV
CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012
osv·2012-06-07·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
No detection rules found.
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-16]
bugzilla·2012-04-19·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-16]
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-17]
bugzilla·2012-04-19·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-17]
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-17]
please see the bug #813768 for more details on this vulnerability
Discussion:
Thank you for this bug report, Pádraig. Have opened #813768 for public audience.
From what I can tell from looking at the proposed upstream patch:
https://bugzilla.redhat.com/show_bug.cgi?id=813768#c0
this issue would affect the versions of the openstack-nova package, as shipped with Fedora release of 16 and Fedora EPEL 6 (though the proposed patch would need to be backported to apply gracefully against these versions). Are these assumptions correct? Could you confirm that? (so I could create trackers for Fedora-16 and Fedora EPEL-6 openstack-nova package versions too).
Thank you, Jan.
---
openstack-nova-2012.1-2.fc17 has
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [epel-6]
bugzilla·2012-04-19·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101 openstack-nova: No quota enforced on security group rules [epel-6]
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules
bugzilla·2012-04-18·CVSS 3.5
CVE-2012-2101 [LOW] CVE-2012-2101 openstack-nova: No quota enforced on security group rules
CVE-2012-2101 openstack-nova: No quota enforced on security group rules
Created attachment 578328
proposed fix
This is an advance warning of a vulnerability discovered in OpenStack,
to give you, as downstream stakeholders, a chance to coordinate the
release of fixes and reduce the vulnerability window. Please treat the
following information as confidential until the proposed public
disclosure date.
Title: No quota enforced on security group rules
Impact: High
Reporter: Dan Prince
Products: Nova
Affects: All versions
Description:
Dan Prince reported a vulnerability in Nova. He discovered that there
was no limit on the number of security group rules a user can create.
By creating a very large set of rules, an unreasonable number of
iptables rules will be created on compute nodes, resulti
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079551.htmlhttp://secunia.com/advisories/49034http://secunia.com/advisories/49048http://ubuntu.com/usn/usn-1438-1http://www.osvdb.org/81641https://bugs.launchpad.net/nova/+bug/969545https://exchange.xforce.ibmcloud.com/vulnerabilities/75243https://github.com/openstack/nova/commit/1f644d210557b1254f7c7b39424b09a45329ade7https://github.com/openstack/nova/commit/8c8735a73afb16d5856f0aa6088e9ae406c52bebhttps://github.com/openstack/nova/commit/a67db4586f70ed881d65e80035b2a25be195ce64https://lists.launchpad.net/openstack/msg10268.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079434.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/079551.htmlhttp://secunia.com/advisories/49034http://secunia.com/advisories/49048http://ubuntu.com/usn/usn-1438-1http://www.osvdb.org/81641https://bugs.launchpad.net/nova/+bug/969545https://exchange.xforce.ibmcloud.com/vulnerabilities/75243https://github.com/openstack/nova/commit/1f644d210557b1254f7c7b39424b09a45329ade7https://github.com/openstack/nova/commit/8c8735a73afb16d5856f0aa6088e9ae406c52bebhttps://github.com/openstack/nova/commit/a67db4586f70ed881d65e80035b2a25be195ce64https://lists.launchpad.net/openstack/msg10268.html
2012-06-07
Published