cbcvebase.
CVE-2012-3371
published 2012-07-17

CVE-2012-3371: The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote…

PriorityP414low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.85%
76.7th percentile
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2012.1.1-5 (bookworm)nova 2012.1.1-5 (bookworm)
openstackcompute
openstackessex
openstackfolsom
openstacknova>= 0 < 2012.1.1-52012.1.1-5
openstacknova>= 0 < 2012.1.1-52012.1.1-5
openstacknova>= 0 < 2012.1.1-52012.1.1-5
openstacknova>= 0 < 2012.1.1-52012.1.1-5
openstacknova>= 0 < 12.0.0a012.0.0a0

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.