Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14635

Опубликовано: 21 мар. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openstack-neutronWill not fix
Red Hat Fuse 7openstack-neutronNot affected
Red Hat OpenStack Platform 14 (Rocky)openstack-neutronNot affected
Red Hat OpenStack Platform 8 (Liberty)openstack-neutronWill not fix
Red Hat OpenStack Platform 9 (Mitaka)openstack-neutronWill not fix
Red Hat OpenStack Platform 10.0 (Newton)openstack-neutronFixedRHSA-2018:271517.09.2018
Red Hat OpenStack Platform 12.0 (Pike)openstack-neutronFixedRHSA-2018:379205.12.2018
Red Hat OpenStack Platform 13.0 (Queens)openstack-neutronFixedRHSA-2018:271017.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1607822openstack-neutron: A router interface out of subnet IP range results in a denial of service

EPSS

Процентиль: 53%
0.00306
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
nvd
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
debian
больше 7 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are abl ...

CVSS3: 6.5
github
больше 3 лет назад

OpensStack Neutron Denial of Service Vulnerability

EPSS

Процентиль: 53%
0.00306
Низкий

6.5 Medium

CVSS3