The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2014-0516.html - | |
References | () http://www.openwall.com/lists/oss-security/2014/03/27/5 - | |
References | () http://www.ubuntu.com/usn/USN-2194-1 - | |
References | () https://bugs.launchpad.net/neutron/+bug/1243327 - |
Information
Published : 2014-05-08 14:29
Updated : 2024-11-21 02:01
NVD link : CVE-2014-0056
Mitre link : CVE-2014-0056
CVE.ORG link : CVE-2014-0056
JSON object : View
Products Affected
canonical
- ubuntu_linux
openstack
- neutron
CWE
CWE-287
Improper Authentication