CVE-2014-3703: Medium severity red hat packstack vulnerability
OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirtvifdriver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3703?
CVE-2014-3703 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-3703?
To fix CVE-2014-3703, ensure the libvirt_vif_driver configuration option is correctly set in the nova.conf file.
What systems are affected by CVE-2014-3703?
CVE-2014-3703 affects OpenStack PackStack version 2012.2.1 when the Open vSwitch monolithic plug-in is not used.
What could happen if CVE-2014-3703 is exploited?
If exploited, CVE-2014-3703 allows remote attackers to bypass firewall protections, leading to unauthorized access.
Is there a patch available for CVE-2014-3703?
Yes, a patch is available in the form of configuration changes to mitigate the effects of CVE-2014-3703.