CVE-2018-14635
Last modified
CVE-2018-14635 is a vulnerability of currently unknown severity. When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. EPSS estimates a 2.53% chance of exploitation in the next 30 days.
Description
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Openstack | 10 | — |
| Redhat | Openstack | 12 | — |
| Redhat | Openstack | 13 | — |
| Openstack | Neutron | >= 11.0.0, <= 11.0.5 | — |
| Openstack | Neutron | >= 12.0.0, <= 12.0.3 | — |
| Openstack | Neutron | 13.0.0.0 | B1 |
References
- https://access.redhat.com/errata/RHSA-2018:2710Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2715Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2721Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3792Third Party Advisory
- https://bugs.launchpad.net/neutron/+bug/1757482Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14635Issue Tracking, Patch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2710Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2715Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2721Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3792Third Party Advisory
- https://bugs.launchpad.net/neutron/+bug/1757482Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14635Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14635?
How severe is CVE-2018-14635?
How do I fix CVE-2018-14635?
Are you affected by CVE-2018-14635?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
