6.8
CVSSv2

CVE-2015-3280

Published: 26/10/2015 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

OpenStack Compute (nova) prior to 2014.2.4 (juno) and 2015.1.x prior to 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

Vendor Advisories

Debian Bug report logs - #798883 CVE-2015-3280 Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 13 Sep 2015 20:12:06 UTC Severity: important Tags: security Found in version nova/201510-1 Fixed in version ...
Several security issues were fixed in OpenStack Nova ...