CVE-2015-3241

OpenStack Compute <2015.1.1-2014.2.3 - DoS

Title source: llm

Description

OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.

Scores

EPSS 0.0197
EPSS Percentile 83.3%

Classification

CWE
CWE-399
Status draft

Affected Products (2)

openstack/nova < 2014.2.3
pypi/nova < 112.0.0.0b3PyPI

Timeline

Published Sep 08, 2015
Tracked Since Feb 18, 2026