Algorithmic Complexity Vulnerability in OpenStack Compute by OpenStack
CVE-2013-4185

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
29 October 2013

Summary

An algorithmic complexity vulnerability exists in OpenStack Compute (Nova) versions prior to 2013.1.3 and Havana before havana-3. This flaw arises from the improper handling of network source security group policy updates, which can be exploited by remote authenticated users. By executing a substantial number of server-creation operations, attackers can initiate excessive update requests that lead to denial of service, resulting in a significant consumption of nova-network resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.