First published: Wed Jun 17 2015(Updated: )
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | >=2014.2<=2014.2.3 | |
OpenStack Nova | >=2015.1.0<=2015.1.1 | |
pip/nova | <12.0.0.0b3 | 112.0.0.0b3 |
>=2014.2<=2014.2.3 | ||
>=2015.1.0<=2015.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.