OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirtvifdriver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.
Yair Fried of Red Hat reports:
A regression from Grizzly and Havana exists in the PackStack rules deployed to Neutron. Specifically when default security groups are enabled they are not enforced, allowing connectivity to systems that should be blocked by the security groups.
External references: https://review.openstack.org/#/c/62702/