CVE Vulnerabilities

CVE-2012-2101

Published: Jun 07, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.

Affected Software

NameVendorStart VersionEnd Version
NovaOpenstack2011.3 (including)2011.3 (including)
NovaOpenstack2012.1 (including)2012.1 (including)
NovaOpenstackfolsom (including)folsom (including)
NovaUbuntudevel*
NovaUbuntunatty*
NovaUbuntuoneiric*
NovaUbuntuprecise*
NovaUbuntuquantal*

References