CVE-2017-17051

HIGH

OpenStack Nova 16.0.3 - Authenticated Denial of Service via Repeated Instance Rebuild

Title source: llm
STIX 2.1

Description

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://review.openstack.org/521662
Vendor Advisory x_refsource_confirm
https://security.openstack.org/ossa/OSSA-2017-006.html
Vendor Advisory x_refsource_confirm
https://review.openstack.org/523214
Issue Tracking, Third Party Advisory x_refsource_confirm
https://launchpad.net/bugs/1732976
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102102

Scores

CVSS v3 8.6
EPSS 0.0084
EPSS Percentile 75.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
openstack/nova 16.0.3
pypi/nova 0 - 16.0.4PyPI
Published Dec 05, 2017
Tracked Since Feb 18, 2026