OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade neutron | Jul 30, 2024 | Nov 24, 2014 |
| Oracle Solaris | — | Upgrade cloud/openstack/neutron to version 0.2013.2.3-0.175.2.6.0.2.0 on Solaris 11.2 | May 29, 2017 | Nov 24, 2014 |
| Ubuntu | — | Upgrade neutron | Nov 19, 2024 | Nov 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub