PYSEC-2018-93

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/neutron/PYSEC-2018-93.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2018-93
Aliases
Published
2018-09-10T19:29:00Z
Modified
2024-04-10T18:58:07.717402Z
Summary
[none]
Details

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.

References

Affected packages

PyPI / neutron

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.6
Introduced
12.0.0
Fixed
12.0.4

Affected versions

0.*

0.0

10.*

10.0.5
10.0.6
10.0.7

11.*

11.0.3
11.0.4
11.0.5

12.*

12.0.0
12.0.1
12.0.2
12.0.3