CVE-2013-4185
published 2013-10-29CVE-2013-4185: Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.09%
79.5th percentile
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2013.1.2-3 (bookworm) | nova 2013.1.2-3 (bookworm) |
| openstack | compute | >= 2013.1 < 2013.1.3 | 2013.1.3 |
| openstack | compute | >= 2013.2 < 2013.2.3 | 2013.2.3 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 2013.1.2-3 | 2013.1.2-3 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 6.0
CVE-2013-2256 [MEDIUM] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Nova could be made to crash if it received specially crafted network
requests.
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)
Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)
Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
aut
Red Hat
OpenStack: Nova network source security groups denial of service
vendor_redhat·2013-08-06·CVSS 4.0
CVE-2013-4185 [MEDIUM] OpenStack: Nova network source security groups denial of service
OpenStack: Nova network source security groups denial of service
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4185: nova - Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3...
vendor_debian·2013·CVSS 4.0
CVE-2013-4185 [MEDIUM] CVE-2013-4185: nova - Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3...
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
Scope: local
bookworm: resolved (fixed in 2013.1.2-3)
bullseye: resolved (fixed in 2013.1.2-3)
forky: resolved (fixed in 2013.1.2-3)
sid: resolved (fixed in 2013.1.2-3)
trixie: resolved (fixed in 2013.1.2-3)
GHSA
OpenStack Nova Denial of Service in network source security groups
ghsa·2022-05-14
CVE-2013-4185 [MEDIUM] OpenStack Nova Denial of Service in network source security groups
OpenStack Nova Denial of Service in network source security groups
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
OSV
OpenStack Nova Denial of Service in network source security groups
osv·2022-05-14
CVE-2013-4185 [MEDIUM] OpenStack Nova Denial of Service in network source security groups
OpenStack Nova Denial of Service in network source security groups
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
OSV
CVE-2013-4185: Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013
osv·2013-10-29·CVSS 4.0
CVE-2013-4185 [MEDIUM] CVE-2013-4185: Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [epel-6]
bugzilla·2013-08-08·CVSS 4.0
CVE-2013-4185 [MEDIUM] CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [epel-6]
CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [fedora-all]
bugzilla·2013-08-08·CVSS 4.0
CVE-2013-4185 [MEDIUM] CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [fedora-all]
CVE-2013-4185 openstack-nova: OpenStack: Nova network source security groups denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-4185 OpenStack: Nova network source security groups denial of service
bugzilla·2013-08-05·CVSS 4.0
CVE-2013-4185 [MEDIUM] CVE-2013-4185 OpenStack: Nova network source security groups denial of service
CVE-2013-4185 OpenStack: Nova network source security groups denial of service
Jeremy Stanley ([email protected]) reports:
Title: Denial of Service in Nova network source security groups
Reporter: Vishvananda Ishaya (Nebula)
Products: Nova
Affects: All versions
Vishvananda Ishaya from Nebula reported a denial of service
vulnerability in Nova's handling of network source security group
policy updates. By performing a large number of server creation
operations, the proportion of updates increases quadratically and
may overwhelm nova-network such that it is no longer able to service
other requests in a timely fashion. Only setups relying on
nova-network are affected.
Havana (development branch) fix:
https://review.openstack.org/39541
Grizzly fix:
https://review.openstack.org/39543
Fo
2013-10-29
Published