cbcvebase.
CVE-2012-2101
published 2012-06-07

CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain…

PriorityP413low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.48%
71.1th percentile
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2012.1-2 (bookworm)nova 2012.1-2 (bookworm)
openstacknova
openstacknova
openstacknova
openstacknova>= 0 < 2012.1-22012.1-2
openstacknova>= 0 < 2012.1-22012.1-2
openstacknova>= 0 < 2012.1-22012.1-2
openstacknova>= 0 < 2012.1-22012.1-2
openstacknova>= 0 < 12.0.0a012.0.0a0

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.