CVE-2017-17051
Current Description
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix for OSSA-2017-005 (CVE-2017-16239); however, only Nova stable/pike or later deployments with that fix applied and relying on the default FilterScheduler are affected.
Basic Data
Published | December 05, 2017 |
Last Modified | October 03, 2019 |
Assigner | cve@mitre.org |
Data Type | CVE |
Data Format | MITRE |
Data Version | 4.0 |
Problem Type | CWE-400 |
CVE Data Version | 4.0 |
Base Metric V2
CVSS 2 - Version | 2.0 |
CVSS 2 - Vector String | AV:N/AC:L/Au:S/C:N/I:N/A:P |
CVSS 2 - Access Vector | NETWORK |
CVSS 2 - Access Complexity | LOW |
CVSS 2 - Authentication | SINGLE |
CVSS 2 - Confidentiality Impact | NONE |
CVSS 2 - Availability Impact | PARTIAL |
CVSS 2 - Base Score | 4.0 |
Severity | MEDIUM |
Exploitability Score | 8.0 |
Impact Score | 2.9 |
Obtain All Privilege | false |
Obtain User Privilege | false |
Obtain Other Privilege | false |
Base Metric V3
CVSS 3 - Version | 3.0 |
CVSS 3 - Vector String | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
CVSS 3 - Attack Vector | NETWORK |
CVSS 3 - Attack Complexity | LOW |
CVSS 3 - Privileges Required | NONE |
CVSS 3 - User Interaction | NONE |
CVSS 3 - Scope | CHANGED |
CVSS 3 - Confidentiality Impact | NONE |
CVSS 3 - Integrity Impact | NONE |
CVSS 3 - Availability Impact | HIGH |
CVSS 3 - Base Score | 8.6 |
CVSS 3 - Base Severity | HIGH |
Exploitability Score | 3.9 |
Base Severity | HIGH |
Configurations
-
OR - Configuration 1
Cpe Version | Part | Vendor | Product | Version | Update | Edition | Language | SW Edition | Target SW | Target HW | Other | Version Start Including | Version End Including | Version Start Excluding | Version End Excluding |
2.3 | Application | Openstack | Nova | 16.0.3 | * | * | * | * | * | * | * | |