CVE Vulnerabilities

CVE-2014-0071

Published: Apr 17, 2014 | Modified: Apr 17, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
6.4 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Affected Software

Name Vendor Start Version End Version
Openstack Redhat 4.0 (including) 4.0 (including)
OpenStack 4 for RHEL 6 RedHat openstack-packstack-0:2013.2.1-0.25.dev987.el6ost *

References