Debian Nova vulnerabilities
61 known vulnerabilities affecting debian/nova.
Total CVEs
61
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM36LOW19
Vulnerabilities
Page 3 of 4
CVE-2014-3708P4LOWCVSS 4.0fixed in nova 2014.1.3-6 (bookworm)2014
CVE-2014-3708 [MEDIUM] CVE-2014-3708: nova - OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows rem...
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3
debian
CVE-2013-4185P4LOWCVSS 4.0fixed in nova 2013.1.2-3 (bookworm)2013
CVE-2013-4185 [MEDIUM] CVE-2013-4185: nova - Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3...
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update reques
debian
CVE-2013-4179P4MEDIUMCVSS 5.0fixed in nova 2013.1.3-1 (bookworm)2013
CVE-2013-4179 [MEDIUM] CVE-2013-4179: nova - The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havan...
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Scope: local
bookworm: resolved (fixed in 2013.1.3-1)
bullseye: reso
debian
CVE-2013-1838P4MEDIUMCVSS 4.0fixed in nova 2012.1.1-15 (bookworm)2013
CVE-2013-1838 [MEDIUM] CVE-2013-1838: nova - OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not p...
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
Scope: local
bookworm: resolved (fixed in 2012.1.1-15)
bullseye: res
debian
CVE-2015-2687P4MEDIUMCVSS 4.7fixed in nova 2014.1-1 (bookworm)2015
CVE-2015-2687 [MEDIUM] CVE-2015-2687: nova - OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails all...
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
Scope: local
bookworm: resolved (fixed in 2014.1-1)
bullseye: resolved (fixed in 2014.1-1)
forky: resolved (fixed in 2014.1-1)
sid: resolved (fixed in 2014.1-1)
trixie: resolved (fixed in 2014.1-1)
debian
CVE-2014-8333P4MEDIUMCVSS 4.0fixed in nova 2014.1.3-7 (bookworm)2014
CVE-2014-8333 [MEDIUM] CVE-2014-8333: nova - The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote auth...
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
Scope: local
bookworm: resolved (fixed in 2014.1.3-7)
bullseye: resolved (fixed in 2014.1.3-7)
forky: resolved (fixed in 2014.1.3-7)
sid: resolved (fixed in 2014.1.3-7)
trixie: resol
debian
CVE-2013-4261P4LOWCVSS 3.5fixed in nova 2013.2-1 (bookworm)2013
CVE-2013-4261 [LOW] CVE-2013-4261: nova - OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid fo...
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Scope:
debian
CVE-2013-6437P4MEDIUMCVSS 4.0fixed in nova 2013.2.2 (bookworm)2013
CVE-2013-6437 [MEDIUM] CVE-2013-6437: nova - The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse befo...
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.
Scope: local
bookworm: resolved (fixed in 2013.2.2)
bullseye: re
debian
CVE-2014-0134P4LOWCVSS 3.5fixed in nova 2013.2.2-4 (bookworm)2014
CVE-2014-0134 [LOW] CVE-2014-0134: nova - The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and ...
The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.
Scope: local
bookworm: resolved (fixed in 2013.2.2-4)
bullseye: resolved (fi
debian
CVE-2012-1585P4MEDIUMCVSS 4.0fixed in nova 2012-1~rc3-1 (bookworm)2012
CVE-2012-1585 [MEDIUM] CVE-2012-1585: nova - OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users t...
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
Scope: local
bookworm: resolved (fixed in 2012-1~rc3-1)
bullseye: resolved (fixed in 2012-1~rc3-1)
forky: resolved (fixed in 2012-1~rc3-1)
sid: resolved (fixed in 2012-1~rc3-1)
trixie: resolved (fix
debian
CVE-2012-3371P4LOWCVSS 3.5fixed in nova 2012.1.1-5 (bookworm)2012
CVE-2012-3371 [LOW] CVE-2012-3371: nova - The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1...
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
Scope: local
bookworm: resolved (fixed in 2012.1.1-
debian
CVE-2012-2101P4LOWCVSS 3.5fixed in nova 2012.1-2 (bookworm)2012
CVE-2012-2101 [LOW] CVE-2012-2101: nova - Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of...
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Scope: local
bookworm: resolved (fixed in 2012.1-2)
bullseye: resolved (fi
debian
CVE-2015-9543P4LOWCVSS 3.3fixed in nova 2:20.1.1-1 (bookworm)2015
CVE-2015-9543 [LOW] CVE-2015-9543: nova - An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and...
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websoc
debian
CVE-2014-3608P4LOWCVSS 2.3fixed in nova 2014.1.3-1 (bookworm)2014
CVE-2014-3608 [LOW] CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Sc
debian
CVE-2014-2573P4LOWCVSS 2.3fixed in nova 2014.1-9 (bookworm)2014
CVE-2014-2573 [LOW] CVE-2014-2573: nova - The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not p...
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
Scope: local
bookworm: resolved (fixed in 2014.1-9)
bullseye: resolved
debian
CVE-2022-37394P4LOWCVSS 3.3fixed in nova 2:26.0.0~rc1-3 (bookworm)2022
CVE-2022-37394 [LOW] CVE-2022-37394: nova - An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and...
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service.
debian
CVE-2014-7230P4LOWCVSS 2.1fixed in cinder 2014.1.3-4 (bookworm)2014
CVE-2014-7230 [LOW] CVE-2014-7230: cinder - The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and...
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Scope: local
bookworm: resolved (fixed in 2014.1.3-4)
bullseye: resolved (fixed in 2014.1.3-4)
forky: resolved (fixed in 2014.1.3-4)
s
debian
CVE-2013-4469P4LOWCVSS 2.1fixed in nova 2013.2-3 (bookworm)2013
CVE-2013-4469 [LOW] CVE-2013-4469: nova - OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set...
OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an inc
debian
CVE-2013-4463P4LOWCVSS 2.1fixed in nova 2013.2-3 (bookworm)2013
CVE-2013-4463 [LOW] CVE-2013-4463: nova - OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify th...
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.
Scope: local
bookworm: resolved (fixed in 2013.2-3)
bullseye: resolved (fixed
debian
CVE-2013-7048P4LOWCVSS 3.3fixed in nova 2013.2.2 (bookworm)2013
CVE-2013-7048 [LOW] CVE-2013-7048: nova - OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses wor...
OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
Scope: local
bookworm: resolved (fixed in 2013.2.2)
bullseye: resolved (fixed in 2013.2.2)
forky: resolved (fixed in 2013.2.2)
sid: r
debian