cbcvebase.
CVE-2015-3280
published 2015-10-26

CVE-2015-3280: OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote…

PriorityP428medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
3.35%
87.4th percentile
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiannova< nova 1:12.0.0-2 (bookworm)nova 1:12.0.0-2 (bookworm)
debiannova< nova 2:13.1.0-1 (bookworm)nova 2:13.1.0-1 (bookworm)
openstackcompute
openstacknova>= 0 < 1:12.0.0-21:12.0.0-2
openstacknova>= 0 < 2:13.1.0-12:13.1.0-1
openstacknova>= 0 < 1:12.0.0-21:12.0.0-2
openstacknova>= 0 < 2:13.1.0-12:13.1.0-1
openstacknova>= 0 < 1:12.0.0-21:12.0.0-2
openstacknova>= 0 < 2:13.1.0-12:13.1.0-1
openstacknova>= 0 < 1:12.0.0-21:12.0.0-2
openstacknova>= 0 < 2:13.1.0-12:13.1.0-1
openstacknova>= 0 < 2014.2.42014.2.4
openstacknova>= 0 < 1:2014.1.5-0ubuntu1.71:2014.1.5-0ubuntu1.7
openstacknova>= 2014.2 < 2014.2.42014.2.4
openstacknova>= 2015.1.0 < 2015.1.22015.1.2
openstacknova>= 2015.1.0 < 2015.1.22015.1.2

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.