Openstack Neutron 2014.1.1

CPE Details

Openstack Neutron 2014.1.1
2014.1.1
2014-04-29
09h42 +00:00
2014-04-29
17h48 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openstack:neutron:2014.1.1:*:*:*:*:*:*:*

Informations

Vendor

openstack

Product

neutron

Version

2014.1.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-7821 2014-11-24 14h00 +00:00 OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
4
CVE-2014-3632 2014-10-07 12h00 +00:00 The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.
7.6
CVE-2014-6414 2014-10-02 12h00 +00:00 OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
4
CVE-2014-4615 2014-08-19 16h00 +00:00 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
5
CVE-2014-3555 2014-07-23 12h00 +00:00 OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.
4
CVE-2014-4167 2014-07-11 12h00 +00:00 The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
3.5