Openstack

Designate

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 12.08.2026 22:23:46
  • Zuletzt bearbeitet 13.08.2026 14:17:12

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing...

  • EPSS 0.53%
  • Veröffentlicht 12.08.2026 22:17:12
  • Zuletzt bearbeitet 13.08.2026 14:17:12

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool v...

  • EPSS 1.83%
  • Veröffentlicht 22.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:33:39

Designate does not enforce the DNS protocol limit concerning record set sizes

Exploit
  • EPSS 2.15%
  • Veröffentlicht 31.08.2017 22:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of servic...