Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-10-27 09:59
Updated : 2023-02-12 16:52
NVD link : CVE-2015-5240
Mitre link : CVE-2015-5240
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
openstack
- neutron