Vulnerability Details CVE-2015-3280
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.8%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2015-3280
-
cpe:2.3:a:openstack:nova:2014.2
-
cpe:2.3:a:openstack:nova:2014.2.0
-
cpe:2.3:a:openstack:nova:2014.2.1
-
cpe:2.3:a:openstack:nova:2014.2.2
-
cpe:2.3:a:openstack:nova:2014.2.3
-
cpe:2.3:a:openstack:nova:2015.1.0
-
cpe:2.3:a:openstack:nova:2015.1.1