CVE-2012-2101: Openstack Nova
Low severity, CVSS 3.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Affected products
- Openstack Nova: version 2011.3 only; version 2012.1 only; version folsom only
Published 2012-06-07. Last modified 2026-06-16.