First published: Thu May 08 2014(Updated: )
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | =2012.2 | |
OpenStack Neutron | =2012.2.1 | |
OpenStack Neutron | =2012.2.2 | |
OpenStack Neutron | =2012.2.3 | |
OpenStack Neutron | =2012.2.4 | |
OpenStack Neutron | =2013.1 | |
OpenStack Neutron | =2013.1.1 | |
OpenStack Neutron | =2013.1.2 | |
OpenStack Neutron | =2013.1.3 | |
OpenStack Neutron | =2013.1.4 | |
OpenStack Neutron | =2013.1.5 | |
OpenStack Neutron | =2013.2 | |
OpenStack Neutron | =2013.2.1 | |
OpenStack Neutron | =2013.2.2 | |
Canonical Ubuntu Linux | =13.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.