CVE-2014-3708
published 2014-10-31CVE-2014-3708: OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.78%
84.8th percentile
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.3-6 (bookworm) | nova 2014.1.3-6 (bookworm) |
| openstack | nova | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | nova | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | nova | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | nova | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | nova | >= 0 < 2014.1.4 | 2014.1.4 |
| openstack | nova | >= 2014.1 < 2014.1.4 | 2014.1.4 |
| openstack | nova | >= 2014.2 < 2014.2.1 | 2014.2.1 |
| openstack | nova | >= 2014.2.0 < 2014.2.1 | 2014.2.1 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Compute (Nova) Denial of Service vulnerability
osv·2022-05-14
CVE-2014-3708 [MEDIUM] OpenStack Compute (Nova) Denial of Service vulnerability
OpenStack Compute (Nova) Denial of Service vulnerability
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
GHSA
OpenStack Compute (Nova) Denial of Service vulnerability
ghsa·2022-05-14
CVE-2014-3708 [MEDIUM] OpenStack Compute (Nova) Denial of Service vulnerability
OpenStack Compute (Nova) Denial of Service vulnerability
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
OSV
CVE-2014-3708: OpenStack Compute (Nova) before 2014
osv·2014-10-31·CVSS 4.0
CVE-2014-3708 [MEDIUM] CVE-2014-3708: OpenStack Compute (Nova) before 2014
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Red Hat
openstack-nova: Nova network denial of service through API filtering
vendor_redhat·2014-10-28·CVSS 4.0
CVE-2014-3708 [MEDIUM] CWE-400 openstack-nova: Nova network denial of service through API filtering
openstack-nova: Nova network denial of service through API filtering
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
A denial of service flaw was found in the way OpenStack Compute (nova) looked up VM instances based on an IP address filter. An attacker with sufficient privileges on an OpenStack installation with a large amount of VMs could use this flaw to cause the main nova process to block for an extended amount of time.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2014-3708: nova - OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows rem...
vendor_debian·2014·CVSS 4.0
CVE-2014-3708 [MEDIUM] CVE-2014-3708: nova - OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows rem...
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3-6)
trixie: resolved (fixed in 2014.1.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering [fedora-all]
bugzilla·2014-10-29·CVSS 4.0
CVE-2014-3708 [MEDIUM] CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering [fedora-all]
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering
bugzilla·2014-10-21·CVSS 4.0
CVE-2014-3708 [MEDIUM] CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering
The OpenStack project reports:
""
Title: Nova network DoS through API filtering
Reporter: Mohammed Naser (Vexxhost)
Products: Nova
Versions: up to 2014.1.2
Description:
Mohammed Naser from Vexxhost reported a vulnerability in Nova API
filters. By listing active servers using an ip filter, an authenticated
user may overload nova-network or neutron-server process, resulting in a
denial of services. All Nova setups are affected.
""
Acknowledgements:
Red Hat would like to thank the OpenStack Project for reporting this issue. Upstream acknowledges Mohammed Naser from Vexxhost as the original reporter.
Discussion:
Created attachment 949631
icehouse patch from upstream
---
Created attachment 949632
juno pa
http://lists.openstack.org/pipermail/openstack-announce/2014-October/000301.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0843.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0844.htmlhttp://www.securityfocus.com/bid/70777https://bugs.launchpad.net/nova/+bug/1358583http://lists.openstack.org/pipermail/openstack-announce/2014-October/000301.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0843.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0844.htmlhttp://www.securityfocus.com/bid/70777https://bugs.launchpad.net/nova/+bug/1358583
2014-10-31
Published