CVE-2014-3632: Openstack Neutron

High severity, CVSS 7.6. EPSS: 2.5% chance of exploitation in the next 30 days.

The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.

Affected products

  • Openstack Neutron: from 2014.1, up to and including 2014.1.2

Published 2014-10-07. Last modified 2026-06-17.