CVE Vulnerabilities

CVE-2014-0056

Improper Authentication

Published: May 08, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
4.1 MODERATE
AV:A/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
NeutronOpenstack2012.2 (including)2012.2 (including)
NeutronOpenstack2012.2.1 (including)2012.2.1 (including)
NeutronOpenstack2012.2.2 (including)2012.2.2 (including)
NeutronOpenstack2012.2.3 (including)2012.2.3 (including)
NeutronOpenstack2012.2.4 (including)2012.2.4 (including)
NeutronOpenstack2013.1 (including)2013.1 (including)
NeutronOpenstack2013.1.1 (including)2013.1.1 (including)
NeutronOpenstack2013.1.2 (including)2013.1.2 (including)
NeutronOpenstack2013.1.3 (including)2013.1.3 (including)
NeutronOpenstack2013.1.4 (including)2013.1.4 (including)
NeutronOpenstack2013.1.5 (including)2013.1.5 (including)
NeutronOpenstack2013.2 (including)2013.2 (including)
NeutronOpenstack2013.2.1 (including)2013.2.1 (including)
NeutronOpenstack2013.2.2 (including)2013.2.2 (including)
OpenStack 4 for RHEL 6RedHatopenstack-neutron-0:2013.2.3-7.el6ost*
NeutronUbuntusaucy*
NeutronUbuntuupstream*

Potential Mitigations

References