OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Essex | Openstack | 2012.1 (including) | 2012.1 (including) |
| Folsom | Openstack | 2012.2 (including) | 2012.2 (including) |
| Grizzly | Openstack | 2012.2 (including) | 2012.2 (including) |
| OpenStack Folsom for RHEL 6 | RedHat | openstack-nova-0:2012.2.3-7.el6ost | * |
| Nova | Ubuntu | oneiric | * |
| Nova | Ubuntu | precise | * |
| Nova | Ubuntu | quantal | * |
| Nova | Ubuntu | upstream | * |