Designate
by OpenStack
Source repositories
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-71193 | Cri | 0.55 | 9.6 | 0.01 | Aug 12, 2026 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter… | ||
| CVE-2015-5694 | Med | 0.42 | 6.5 | 0.02 | Nov 22, 2019 | Designate does not enforce the DNS protocol limit concerning record set sizes | ||
| CVE-2015-5695 | Med | 0.42 | 6.5 | 0.02 | Aug 31, 2017 | Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a… | ||
| CVE-2026-71194 | Med | 0.37 | 6.8 | 0.01 | Aug 12, 2026 | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return… | ||
| CVE-2023-6725 | Med | 0.36 | 5.5 | 0.00 | Mar 15, 2024 | An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive… |
- risk 0.55cvss 9.6epss 0.01
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter…
- risk 0.42cvss 6.5epss 0.02
Designate does not enforce the DNS protocol limit concerning record set sizes
- risk 0.42cvss 6.5epss 0.02
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a…
- risk 0.37cvss 6.8epss 0.01
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return…
- risk 0.36cvss 5.5epss 0.00
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive…