CVE-2012-3371: Input Validation
Published Jul 17, 2012
·Updated
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:schedulerhints section.
Affected Software
4 affected componentsFixes available
pip/Nova<12.0.0a0
12.0.0a0
Openstack Compute=2012.2
Openstack Essex=2012.1
Openstack folsom=2012.2
Remediation
Event History
Jul 17, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·05:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-3371?
CVE-2012-3371 is classified as a medium severity vulnerability due to its potential for causing a denial of service.
2
How do I fix CVE-2012-3371?
To fix CVE-2012-3371, upgrade to Nova version 12.0.0a0 or later.
3
What systems are affected by CVE-2012-3371?
CVE-2012-3371 affects OpenStack Compute Nova versions 2012.1 and 2012.2.
4
What type of attack does CVE-2012-3371 enable?
CVE-2012-3371 enables attackers to perform denial of service attacks by causing excessive database lookup calls.
5
Who can exploit CVE-2012-3371?
CVE-2012-3371 can be exploited by remote authenticated users.