CVE-2014-8333: Medium severity red hat enterprise linux vulnerability
Published Oct 31, 2014
·Updated
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
Affected Software
8 affected componentsFixes available
pip/nova<12.0.0a0
12.0.0a0
All of the following
Any of the following
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Openstack=5.0
Openstack Nova>=2014.1<2014.1.4
redhat Openstack=5.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
Remediation
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-8333?
CVE-2014-8333 has a medium severity level as it allows authenticated users to exploit resources, causing denial of service by consuming disk space.
2
How do I fix CVE-2014-8333?
To fix CVE-2014-8333, update your OpenStack Nova to version 2014.1.4 or later.
3
Which versions of Nova are affected by CVE-2014-8333?
CVE-2014-8333 affects all versions of Nova prior to 2014.1.4.
4
Can Red Hat Enterprise Linux versions be affected by CVE-2014-8333?
Red Hat Enterprise Linux versions 6.0 and 7.0 are not vulnerable to CVE-2014-8333.
5
What impact does CVE-2014-8333 have on my OpenStack installation?
CVE-2014-8333 can lead to a denial of service by allowing remote authenticated users to delete instances in the resize state, leading to disk consumption.