First published: Fri Oct 31 2014(Updated: )
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | >=2014.1<2014.1.4 | |
OpenStack Nova | >=2014.2<2014.2.1 | |
Redhat Openstack | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3708 has been classified as a denial of service vulnerability that can lead to significant CPU consumption.
To fix CVE-2014-3708, upgrade OpenStack Compute (Nova) to version 2014.1.4 or later, or to version 2014.2.1 or later.
CVE-2014-3708 affects users of OpenStack Compute (Nova) prior to version 2014.1.4 and certain versions of OpenStack 2014.2.x.
Exploiting CVE-2014-3708 can lead to denial of service conditions due to excessive CPU consumption by authenticated remote users.
While CVE-2014-3708's vulnerabilities were addressed in later versions, systems still running older versions remain at risk.