CVE Vulnerabilities

CVE-2015-7944

Published: Aug 18, 2017 | Modified: Sep 08, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.

Affected Software

Name Vendor Start Version End Version
Ganeti Spi-inc * 2.9.6 (including)
Ganeti Spi-inc 2.10.0 (including) 2.10.0 (including)
Ganeti Spi-inc 2.10.0-beta1 (including) 2.10.0-beta1 (including)
Ganeti Spi-inc 2.10.0-rc1 (including) 2.10.0-rc1 (including)
Ganeti Spi-inc 2.10.0-rc2 (including) 2.10.0-rc2 (including)
Ganeti Spi-inc 2.10.0-rc3 (including) 2.10.0-rc3 (including)
Ganeti Spi-inc 2.10.1 (including) 2.10.1 (including)
Ganeti Spi-inc 2.10.2 (including) 2.10.2 (including)
Ganeti Spi-inc 2.10.3 (including) 2.10.3 (including)
Ganeti Spi-inc 2.10.4 (including) 2.10.4 (including)
Ganeti Spi-inc 2.10.5 (including) 2.10.5 (including)
Ganeti Spi-inc 2.10.6 (including) 2.10.6 (including)
Ganeti Spi-inc 2.10.7 (including) 2.10.7 (including)
Ganeti Spi-inc 2.11.0 (including) 2.11.0 (including)
Ganeti Spi-inc 2.11.0-beta1 (including) 2.11.0-beta1 (including)
Ganeti Spi-inc 2.11.0-rc1 (including) 2.11.0-rc1 (including)
Ganeti Spi-inc 2.11.1 (including) 2.11.1 (including)
Ganeti Spi-inc 2.11.2 (including) 2.11.2 (including)
Ganeti Spi-inc 2.11.3 (including) 2.11.3 (including)
Ganeti Spi-inc 2.11.4 (including) 2.11.4 (including)
Ganeti Spi-inc 2.11.5 (including) 2.11.5 (including)
Ganeti Spi-inc 2.11.6 (including) 2.11.6 (including)
Ganeti Spi-inc 2.11.7 (including) 2.11.7 (including)
Ganeti Spi-inc 2.12.0 (including) 2.12.0 (including)
Ganeti Spi-inc 2.12.0-beta1 (including) 2.12.0-beta1 (including)
Ganeti Spi-inc 2.12.0-rc1 (including) 2.12.0-rc1 (including)
Ganeti Spi-inc 2.12.0-rc2 (including) 2.12.0-rc2 (including)
Ganeti Spi-inc 2.12.1 (including) 2.12.1 (including)
Ganeti Spi-inc 2.12.2 (including) 2.12.2 (including)
Ganeti Spi-inc 2.12.3 (including) 2.12.3 (including)
Ganeti Spi-inc 2.12.4 (including) 2.12.4 (including)
Ganeti Spi-inc 2.12.5 (including) 2.12.5 (including)
Ganeti Spi-inc 2.13.0 (including) 2.13.0 (including)
Ganeti Spi-inc 2.13.0-beta1 (including) 2.13.0-beta1 (including)
Ganeti Spi-inc 2.13.0-rc1 (including) 2.13.0-rc1 (including)
Ganeti Spi-inc 2.13.1 (including) 2.13.1 (including)
Ganeti Spi-inc 2.13.2 (including) 2.13.2 (including)
Ganeti Spi-inc 2.14.0 (including) 2.14.0 (including)
Ganeti Spi-inc 2.14.0-beta1 (including) 2.14.0-beta1 (including)
Ganeti Spi-inc 2.14.0-beta2 (including) 2.14.0-beta2 (including)
Ganeti Spi-inc 2.14.0-rc1 (including) 2.14.0-rc1 (including)
Ganeti Spi-inc 2.14.0-rc2 (including) 2.14.0-rc2 (including)
Ganeti Spi-inc 2.14.1 (including) 2.14.1 (including)
Ganeti Spi-inc 2.15.0 (including) 2.15.0 (including)
Ganeti Spi-inc 2.15.0-beta1 (including) 2.15.0-beta1 (including)
Ganeti Spi-inc 2.15.0-rc1 (including) 2.15.0-rc1 (including)
Ganeti Spi-inc 2.15.1 (including) 2.15.1 (including)

References