Comment 20 for bug 962515

Revision history for this message
Thierry Carrez (ttx) wrote :

Proposed impact description:

Title: Long server names grow nova-api log files significantly
Impact: High
Reporter: Dan Prince
Products: Nova
Affects: All versions

Description:
Dan Prince reported a vulnerability in OpenStack Compute (Nova) API servers. By PUTing or POSTing extremely long server names to the OpenStack API, any authenticated user may grow nova-api log files significantly, potentially resulting in disk space exhaustion and denial of service to the affected nova-api nodes. Only setups running the OpenStack API are affected.