CVE-2015-3280
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances…
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- openstack/nova
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-1898.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76553Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1392527Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-017.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1898.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.securityfocus.com/bid/76553Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1392527Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2015-017.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.