Debian Neutron vulnerabilities
25 known vulnerabilities affecting debian/neutron.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM12LOW6
Vulnerabilities
Page 2 of 2
CVE-2014-7821P4MEDIUMCVSS 4.0fixed in neutron 2014.1.3-6 (bookworm)2014
CVE-2014-7821 [MEDIUM] CVE-2014-7821: neutron - OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote aut...
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3-6)
tri
debian
CVE-2015-5240P4LOWCVSS 3.5fixed in neutron 1:7.0.0-1 (bookworm)2015
CVE-2015-5240 [LOW] CVE-2015-5240: neutron - Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, ...
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
Scope: local
bookworm: resolved (fixed in 1:7.0.0-1)
bu
debian
CVE-2014-0056P4LOWCVSS 2.1fixed in neutron 2013.2.2-4 (bookworm)2014
CVE-2014-0056 [LOW] CVE-2014-0056: neutron - The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tena...
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Scope: local
bookworm: resolved (fixed in 2013.2.2-4)
bullseye: resolved (fixed in 2013.2.2-4)
forky: resolved (fixed in 2013.2.
debian
CVE-2014-3555P4MEDIUMCVSS 4.0fixed in neutron 2014.1.1-3 (bookworm)2014
CVE-2014-3555 [MEDIUM] CVE-2014-3555: neutron - OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-...
OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.
Scope: local
bookworm: resolved (fixed in 2014.1.1-3)
bullseye: resolved (fixed in 2014.1.1-3)
forky: resolved (fixed in 2014.1.1-3)
debian
CVE-2014-4167P4LOWCVSS 3.5fixed in neutron 2014.1.1-1 (bookworm)2014
CVE-2014-4167 [LOW] CVE-2014-4167: neutron - The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and J...
The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
Scope: local
bookworm: resolved (fixed in 2014.1.1-1)
bullseye: resolved (fixed in 2014.1.1-1)
forky: resolved (fixed in 2014
debian
← Previous2 / 2