CVE-2014-3708: Medium severity openstack compute (nova) vulnerability
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3708?
CVE-2014-3708 has been classified as a denial of service vulnerability that can lead to significant CPU consumption.
How do I fix CVE-2014-3708?
To fix CVE-2014-3708, upgrade OpenStack Compute (Nova) to version 2014.1.4 or later, or to version 2014.2.1 or later.
Who is affected by CVE-2014-3708?
CVE-2014-3708 affects users of OpenStack Compute (Nova) prior to version 2014.1.4 and certain versions of OpenStack 2014.2.x.
What is the impact of exploiting CVE-2014-3708?
Exploiting CVE-2014-3708 can lead to denial of service conditions due to excessive CPU consumption by authenticated remote users.
Is CVE-2014-3708 still a concern today?
While CVE-2014-3708's vulnerabilities were addressed in later versions, systems still running older versions remain at risk.