cbcvebase.
CVE-2014-3708
published 2014-10-31

CVE-2014-3708: OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an…

medium4CVSS 3.1
AVNACLAuSCNINAP
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2014.1.3-6 (bookworm)nova 2014.1.3-6 (bookworm)
openstacknova>= 0 < 2014.1.3-62014.1.3-6
openstacknova>= 0 < 2014.1.3-62014.1.3-6
openstacknova>= 0 < 2014.1.3-62014.1.3-6
openstacknova>= 0 < 2014.1.3-62014.1.3-6
openstacknova>= 0 < 2014.1.42014.1.4
openstacknova>= 2014.1 < 2014.1.42014.1.4
openstacknova>= 2014.2 < 2014.2.12014.2.1
openstacknova>= 2014.2.0 < 2014.2.12014.2.1
redhatopenstack

CVSS provenance

nvd4.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM