CVE-2013-4261
Last modified
CVE-2013-4261 is a vulnerability of currently unknown severity. OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.. EPSS estimates a 1.74% chance of exploitation in the next 30 days.
Description
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Folsom | <= - |
| Openstack | Grizzly | <= - |
| Redhat | Openstack | 3.0 |
References
- http://rhn.redhat.com/errata/RHSA-2013-1199.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=999164Exploit, Patch
- http://rhn.redhat.com/errata/RHSA-2013-1199.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=999164Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4261?
How severe is CVE-2013-4261?
How do I fix CVE-2013-4261?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4255The policy definition evaluator in Condor 7.5.4, 8.0.0, and …
- CVE-2013-4256Multiple stack-based and heap-based buffer overflows in Netw…
- CVE-2013-4257Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4258Format string vulnerability in the osLogMsg function in serv…
- CVE-2013-4259runner/connection_plugins/ssh.py in Ansible before 1.2.3, wh…
- CVE-2013-4260lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2…
- CVE-2013-4262svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the…
- CVE-2013-4263libavfilter in FFmpeg before 2.0.1 has unspecified impact an…
- CVE-2013-4264The kempf_decode_tile function in libavcodec/g2meet.c in FFm…
- CVE-2013-4265The av_reallocp_array function in libavutil/mem.c in FFmpeg …
- CVE-2013-4266Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-4267Ajaxeplorer before 5.0.1 allows remote attackers to execute …9.8
Are you affected by CVE-2013-4261?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
