CVE-2014-3708: Openstack Nova

Medium severity, CVSS 4.0. EPSS: 2.8% chance of exploitation in the next 30 days.

OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.

Affected products

  • Openstack Nova: from 2014.1, before 2014.1.4 (fixed in 2014.1.4); from 2014.2, before 2014.2.1 (fixed in 2014.2.1)
  • Red Hat Openstack: version 5.0 only

Published 2014-10-31. Last modified 2026-06-17.