VDB
KO
MEDIUM

GHSA-mfmj-gwg3-vhw7

OpenStack Compute (nova) allows remote authenticated users to cause a denial of service

Details

OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / nova
Introduced in: 0 Fixed in: 2014.2.4
Fix pip install --upgrade 'nova>=2014.2.4'
PyPI / nova
Introduced in: 2015.1.0 Fixed in: 2015.1.2
Fix pip install --upgrade 'nova>=2015.1.2'

References