CVE-2015-3221
OpenStack Neutron Improper Input Validation vulnerability
EPSS 11.3%
描述
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
如何修補 CVE-2015-3221
要修補 CVE-2015-3221,請將受影響套件升級到下列已修補版本。
- PyPI/neutron—升級至 2014.2.4 或更新版本
CVE-2015-3221 正在被利用嗎?
中等 — EPSS 為 11.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2014.2.4, >= 2015.1.0, < 2015.1.1