CVE-2013-4185
Dashboard / Vulnerabilities / CVE-2013-4185
CVE-2013-4185
Published: 29 Oct 2013Last Modified: 7 Jul 2026
Aliases:
Summary:
Details: Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
References: http://rhn.redhat.com/errata/RHSA-2013-1199.html, http://seclists.org/oss-sec/2013/q3/282, https://bugs.launchpad.net/nova/+bug/1184041, https://bugs.launchpad.net/nova/+bug/1184041, http://seclists.org/oss-sec/2013/q3/282
Affected packages
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
