6.8
CVSSv2

CVE-2015-3280

Published: 26/10/2015 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

OpenStack Compute (nova) prior to 2014.2.4 (juno) and 2015.1.x prior to 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

Vendor Advisories

Several security issues were fixed in OpenStack Nova ...
Debian Bug report logs - #798883 CVE-2015-3280 Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 13 Sep 2015 20:12:06 UTC Severity: important Tags: security Found in version nova/201510-1 Fixed in version ...