Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14635

Опубликовано: 10 сент. 2018
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

РелизСтатусПримечание
bionic

released

2:12.0.3-0ubuntu1
cosmic

not-affected

2:13.0.0-0ubuntu4
devel

not-affected

2:13.0.0-0ubuntu4
disco

not-affected

2:13.0.0-0ubuntu4
eoan

not-affected

2:13.0.0-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra-legacy/xenial

needed

esm-infra/bionic

released

2:12.0.3-0ubuntu1
esm-infra/focal

not-affected

2:13.0.0-0ubuntu4
esm-infra/xenial

ignored

end of ESM support, was needed

Показывать по

Ссылки на источники

EPSS

Процентиль: 84%
0.02527
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 8 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
nvd
почти 8 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

CVSS3: 6.5
debian
почти 8 лет назад

When using the Linux bridge ml2 driver, non-privileged tenants are abl ...

CVSS3: 6.5
github
больше 4 лет назад

OpensStack Neutron Denial of Service Vulnerability

EPSS

Процентиль: 84%
0.02527
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3