The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Neutron | Openstack | 2013.1 (including) | 2013.1 (including) |
Neutron | Openstack | 2013.1.1 (including) | 2013.1.1 (including) |
Neutron | Openstack | 2013.1.2 (including) | 2013.1.2 (including) |
Neutron | Openstack | 2013.1.3 (including) | 2013.1.3 (including) |
Neutron | Openstack | 2013.1.4 (including) | 2013.1.4 (including) |
Neutron | Openstack | 2013.1.5 (including) | 2013.1.5 (including) |
Neutron | Openstack | 2013.2 (including) | 2013.2 (including) |
Neutron | Openstack | 2013.2.1 (including) | 2013.2.1 (including) |
Neutron | Openstack | 2013.2.2 (including) | 2013.2.2 (including) |
Neutron | Openstack | 2013.2.3 (including) | 2013.2.3 (including) |
Neutron | Openstack | 2014.1 (including) | 2014.1 (including) |
OpenStack 4 for RHEL 6 | RedHat | openstack-neutron-0:2013.2.3-14.el6ost | * |
Neutron | Ubuntu | saucy | * |
Neutron | Ubuntu | trusty | * |
Neutron | Ubuntu | upstream | * |