CVE Vulnerabilities

CVE-2014-0592

Published: Apr 04, 2014 | Modified: Apr 04, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.

Affected Software

Name Vendor Start Version End Version
Barclamp Crowbar 1.7 (including) 1.7 (including)

References