CVE-2013-1838: OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
(updated )
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
References
- bugs.launchpad.net/nova/+bug/1125468
- bugzilla.redhat.com/show_bug.cgi?id=919648
- exchange.xforce.ibmcloud.com/vulnerabilities/82877
- github.com/advisories/GHSA-63fq-8fp9-vhwq
- github.com/openstack/nova
- github.com/openstack/nova/commit/9561484166f245d0e4602a36351d6cac72dd9426
- github.com/openstack/nova/commit/99429214d4ddb5bdc7de185693b8a53ad50df3c6
- github.com/openstack/nova/commit/efaacdaee116388234558e2682b647d41fe5b149
- lists.launchpad.net/openstack/msg21892.html
- nvd.nist.gov/vuln/detail/CVE-2013-1838
- review.openstack.org/
- review.openstack.org/
- review.openstack.org/
Detect and mitigate CVE-2013-1838 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →