cbcvebase.
CVE-2013-4261
published 2013-10-29

CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging…

PriorityP416low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.74%
75.2th percentile
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2013.2-1 (bookworm)nova 2013.2-1 (bookworm)
openstackfolsom<= -
openstackgrizzly<= -
openstacknova>= 0 < 2013.2-12013.2-1
openstacknova>= 0 < 2013.2-12013.2-1
openstacknova>= 0 < 2013.2-12013.2-1
openstacknova>= 0 < 2013.2-12013.2-1
redhatopenstack

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_ubuntu6.0MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.