Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x634-34m9-96mp

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpensStack Neutron Denial of Service Vulnerability

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

Пакеты

Наименование

neutron

pip
Затронутые версииВерсия исправления

= 13.0.0.0b1

13.0.0.0b2

Наименование

neutron

pip
Затронутые версииВерсия исправления

< 11.0.6

11.0.6

Наименование

neutron

pip
Затронутые версииВерсия исправления

>= 12.0.0, < 12.0.4

12.0.4

EPSS

Процентиль: 53%
0.00306
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
redhat
почти 8 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
nvd
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
debian
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are abl ...

EPSS

Процентиль: 53%
0.00306
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-20