CVE-2012-3371

Openstack Compute < 12.0.0a0 - Improper Input Validation

Title source: rule

Description

The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.

Scores

EPSS 0.0088
EPSS Percentile 75.1%

Classification

CWE
CWE-20
Status draft

Affected Products (4)

openstack/compute
openstack/essex
openstack/folsom
pypi/Nova < 12.0.0a0PyPI

Timeline

Published Jul 17, 2012
Tracked Since Feb 18, 2026