Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3555

Опубликовано: 21 июл. 2014
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.

A denial of service flaw was found in neutron's handling of allowed address pairs. As there was no enforced quota on the amount of allowed address pairs, a sufficiently authorized user could possibly create a large number of firewall rules, impacting performance or potentially rendering a compute node unusable.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1118833openstack-neutron: Denial of Service in Neutron allowed address pair

EPSS

Процентиль: 75%
0.00875
Низкий

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.

nvd
больше 11 лет назад

OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.

debian
больше 11 лет назад

OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno be ...

github
больше 3 лет назад

OpenStack Neutron allows remote authenticated users to cause a denial of service

EPSS

Процентиль: 75%
0.00875
Низкий

3.5 Low

CVSS2