The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2014-05-08 07:29
Updated : 2023-02-12 16:30
NVD link : CVE-2014-0056
Mitre link : CVE-2014-0056
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
canonical
- ubuntu_linux
openstack
- neutron