CVE-2012-2101

Openstack Nova < 12.0.0a0 - Access Control

Title source: rule

Description

Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.

Scores

EPSS 0.0089
EPSS Percentile 75.2%

Classification

CWE
CWE-264
Status draft

Affected Products (4)

openstack/nova
openstack/nova
openstack/nova
pypi/nova < 12.0.0a0PyPI

Timeline

Published Jun 07, 2012
Tracked Since Feb 18, 2026