CVE-2017-16239Medium· 6.5▾ SunlitOpenStack Nova Filter Scheduler Bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
1.4% → 1.4%
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are affected. Because of the regression described in Launchpad Bug #1732947, the preferred fix is a 14.x version after 14.0.10, a 15.x version after 15.0.8, or a 16.x version after 16.0.3.
nova >= 16.0.0, < 16.0.3nova >= 15.0.0, < 15.0.8nova >= 14.0.0, < 14.0.10Upgrade to a patched release:
nova 16.0.3nova 15.0.8nova 14.0.10Connected by shared product, vendor, weakness, or advisory.
CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2011-4596MediumOpenStack Nova Multiple directory traversal vulnerabilities
CVE-2012-1585MediumOpenStack Nova Long server names grow nova-api log files significantly
CVE-2013-4185MediumOpenStack Nova Denial of Service in network source security groups