GHSA-wf44-4mgj-rwvxMedium

OpenStack Neutron Improper Input Validation vulnerability

Published
May 14, 2022
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

🎯 Affected products2

  • pip/neutron:>= 2015.1.0, < 2015.1.1
  • pip/neutron:>= 2000, < 2014.2.4

🔗 References (11)