{"id":"CVE-2013-4261","details":"OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the console log.","modified":"2026-04-10T03:42:55.893540Z","published":"2013-10-29T22:55:02Z","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-1199.html"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/nova/+bug/1215091"},{"type":"EVIDENCE","url":"https://bugzilla.redhat.com/show_bug.cgi?id=999164"},{"type":"FIX","url":"http://seclists.org/oss-sec/2013/q3/595"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=999164"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=999271"}],"schema_version":"1.7.5"}