VULNERABILITY INTELLIGENCE
CVE-2012-3371
CVSS score3.5 LOW
EPSS probability1.86%
CISA KEVNot currently listed
Published2012-07-17
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Description
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com — Exploit
- secalert@redhat.com — Exploit, Patch
- secalert@redhat.com
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Exploit
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Patch
- af854a3a-2127-422b-91ae-364da2661108