ossa/ossa/OSSA-2014-037.yaml

60 lines
1.2 KiB
YAML

date: 2014-10-21
id: OSSA-2014-037
title: 'Nova VMware instance in resize state may leak'
description: 'Zhu Zhu from IBM reported a vulnerability in Nova VMware driver. If an
authenticated user deletes an instance while it is in resize state, it
will cause the original instance to not be deleted. An attacker can use
this to launch a denial of service attack. All Nova VMware setups are
affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-October/000298.html
affected-products:
- product: nova
version: up to 2014.1.3
vulnerabilities:
- cve-id: CVE-2014-8333
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:N/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: CWE-772
reporters:
- name: 'Zhu Zhu'
affiliation: IBM
reported:
- CVE-2014-8333
issues:
links:
- https://launchpad.net/bugs/1359138
type: launchpad
reviews:
juno:
- https://review.openstack.org/118595
icehouse:
- https://review.openstack.org/125492
type: gerrit