CVE-2014-3608
published 2014-10-06CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service…
PriorityP411low2.7CVSS 2.0
AVAACLAuSCNINAP
EPSS
1.71%
74.9th percentile
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.3-1 (bookworm) | nova 2014.1.3-1 (bookworm) |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1.3 | 2014.1.3 |
| openstack | nova | >= 0 < 1:2014.1.3-0ubuntu1.1 | 1:2014.1.3-0ubuntu1.1 |
| openstack | nova | 2013.2 – 2013.2.4 | — |
| openstack | nova | >= 2014.1 < 2014.1.3 | 2014.1.3 |
CVSS provenance
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
ghsa2.3LOW
osv2.7LOW
vendor_ubuntu2.7LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
osv·2022-05-14·CVSS 2.3
CVE-2014-3608 [LOW] OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
GHSA
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
ghsa·2022-05-14·CVSS 2.3
CVE-2014-3608 [LOW] OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
OSV
nova vulnerabilities
osv·2014-11-11·CVSS 2.7
CVE-2014-3608 [LOW] nova vulnerabilities
nova vulnerabilities
Garth Mollett discovered that OpenStack Nova did not properly clean up an
instance when using rescue mode with the VMWare driver. A remove
authenticated user could exploit this to bypass intended quota limits. By
default, Ubuntu does not use the VMWare driver. (CVE-2014-3608)
Amrith Kumar discovered that OpenStack Nova did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Nova log files could obtain access to sensitive information.
(CVE-2014-7230)
OSV
CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014
osv·2014-10-06·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Ubuntu
OpenStack Nova vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 2.7
CVE-2014-3608 [LOW] OpenStack Nova vulnerabilities
Title: OpenStack Nova vulnerabilities
Summary: OpenStack Nova could be made to expose sensitive information.
Garth Mollett discovered that OpenStack Nova did not properly clean up an
instance when using rescue mode with the VMWare driver. A remove
authenticated user could exploit this to bypass intended quota limits. By
default, Ubuntu does not use the VMWare driver. (CVE-2014-3608)
Amrith Kumar discovered that OpenStack Nova did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Nova log files could obtain access to sensitive information.
(CVE-2014-7230)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
vendor_redhat·2014-10-02·CVSS 2.3
CVE-2014-3608 [LOW] CWE-400 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...
vendor_debian·2014·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
forky: resolved (fixed in 2014.1.3-1)
sid: resolved (fixed in 2014.1.3-1)
trixie: resolved (fixed in 2014.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
bugzilla·2014-10-03·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
bugzilla·2014-10-01·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
The OpenStack project reports:
""
Title: Nova VMware driver still leaks rescued images
Reporter: Garth Mollett (Red Hat)
Products: Nova
Versions: up to 2014.1.2
Description:
Garth Mollett from Red Hat reported an incomplete fix to OSSA-2014-017
(CVE-2014-2573), a vulnerability affecting Nova. If an authenticated user
places an instance into rescue, and then issues a suspend command it will
cause the instance to enter an ERROR state. Nova does not clean up an
instance in this state correctly upon deletion. An attacker can use this to
launch a denial of service attack. Only setups using the Nova VMware driver
are affected by this flaw.
""
Acknowledgements:
This issue was discove
http://rhn.redhat.com/errata/RHSA-2014-1781.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1782.htmlhttp://seclists.org/oss-sec/2014/q4/65http://www.securityfocus.com/bid/70220https://bugs.launchpad.net/nova/+bug/1338830http://rhn.redhat.com/errata/RHSA-2014-1781.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1782.htmlhttp://seclists.org/oss-sec/2014/q4/65http://www.securityfocus.com/bid/70220https://bugs.launchpad.net/nova/+bug/1338830
2014-10-06
Published