{"id":"CVE-2014-3708","aliases":["GHSA-43hc-pwvx-pmfg","PYSEC-2026-863"],"title":"OpenStack Compute (Nova) Denial of Service vulnerability","summary":"OpenStack Compute (Nova) Denial of Service vulnerability","severity":"medium","vendor":"nova","product":"nova","ecosystem":"pip","affected":["nova < 2014.1.4","nova >= 2014.2.0, < 2014.2.1"],"patched":["nova 2014.1.4","nova 2014.2.1"],"published":"2022-05-14","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:29.845135613Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-43hc-pwvx-pmfg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3708"},{"url":"https://access.redhat.com/errata/RHSA-2015:0843"},{"url":"https://access.redhat.com/errata/RHSA-2015:0844"},{"url":"https://access.redhat.com/security/cve/CVE-2014-3708"},{"url":"https://bugs.launchpad.net/nova/+bug/1358583"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1154951"},{"url":"https://opendev.org/openstack/nova"},{"url":"https://web.archive.org/web/20200901000000*/http://www.securityfocus.com/bid/70777"},{"url":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000301.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0843.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0844.html"},{"url":"http://www.securityfocus.com/bid/70777"}],"tags":["osv","pip"],"epss":0.02806,"epssPercentile":0.85801,"ingestedAt":"2026-07-08T18:25:45.241Z","slug":"CVE-2014-3708","body":"## Overview\n\nOpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.\n\n## Affected packages\n\n- `nova < 2014.1.4`\n- `nova >= 2014.2.0, < 2014.2.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nova 2014.1.4`\n- `nova 2014.2.1`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}