CVE-2014-8333
published 2014-10-31CVE-2014-8333: The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an…
PriorityP416medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.01%
78.7th percentile
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.3-7 (bookworm) | nova 2014.1.3-7 (bookworm) |
| openstack | nova | >= 0 < 2014.1.3-7 | 2014.1.3-7 |
| openstack | nova | >= 0 < 2014.1.3-7 | 2014.1.3-7 |
| openstack | nova | >= 0 < 2014.1.3-7 | 2014.1.3-7 |
| openstack | nova | >= 0 < 2014.1.3-7 | 2014.1.3-7 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | >= 2014.1 < 2014.1.4 | 2014.1.4 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova VMware instance leak potentially leading to compute DoS
osv·2022-05-14
CVE-2014-8333 [MEDIUM] OpenStack Nova VMware instance leak potentially leading to compute DoS
OpenStack Nova VMware instance leak potentially leading to compute DoS
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
GHSA
OpenStack Nova VMware instance leak potentially leading to compute DoS
ghsa·2022-05-14
CVE-2014-8333 [MEDIUM] OpenStack Nova VMware instance leak potentially leading to compute DoS
OpenStack Nova VMware instance leak potentially leading to compute DoS
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
OSV
CVE-2014-8333: The VMware driver in OpenStack Compute (Nova) before 2014
osv·2014-10-31·CVSS 4.0
CVE-2014-8333 [MEDIUM] CVE-2014-8333: The VMware driver in OpenStack Compute (Nova) before 2014
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
Red Hat
openstack-nova: Nova VMware instance in resize state may leak
vendor_redhat·2014-08-20·CVSS 4.0
CVE-2014-8333 [MEDIUM] CWE-772 openstack-nova: Nova VMware instance in resize state may leak
openstack-nova: Nova VMware instance in resize state may leak
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
A flaw was found in the OpenStack Compute (nova) VMWare driver, which could allow an authenticated user to delete an instance while it was in the resize state, causing the instance to remain on the back end. A malicious user could use this flaw to cause a denial of service by exhausting all available resources on the system.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2014-8333: nova - The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote auth...
vendor_debian·2014·CVSS 4.0
CVE-2014-8333 [MEDIUM] CVE-2014-8333: nova - The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote auth...
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
Scope: local
bookworm: resolved (fixed in 2014.1.3-7)
bullseye: resolved (fixed in 2014.1.3-7)
forky: resolved (fixed in 2014.1.3-7)
sid: resolved (fixed in 2014.1.3-7)
trixie: resolved (fixed in 2014.1.3-7)
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack-announce/2014-October/000298.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0843.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0844.htmlhttp://secunia.com/advisories/60531https://bugs.launchpad.net/nova/+bug/1359138http://lists.openstack.org/pipermail/openstack-announce/2014-October/000298.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0843.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0844.htmlhttp://secunia.com/advisories/60531https://bugs.launchpad.net/nova/+bug/1359138
2014-10-31
Published