GHSA-wf44-4mgj-rwvx

Suggest an improvement
Source
https://github.com/advisories/GHSA-wf44-4mgj-rwvx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wf44-4mgj-rwvx/GHSA-wf44-4mgj-rwvx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wf44-4mgj-rwvx
Aliases
Published
2022-05-14T02:19:50Z
Modified
2026-08-07T19:15:32Z
Summary
OpenStack Neutron Improper Input Validation vulnerability
Details

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-02-08T18:00:32Z",
    "nvd_published_at": "2015-08-26T19:59:00Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / neutron

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2000
Fixed
2014.2.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wf44-4mgj-rwvx/GHSA-wf44-4mgj-rwvx.json"

PyPI / neutron

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2015.1.0
Fixed
2015.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wf44-4mgj-rwvx/GHSA-wf44-4mgj-rwvx.json"