OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Packstack | Redhat | 2012.2.1 (including) | 2012.2.1 (including) |
OpenStack 4 for RHEL 6 | RedHat | openstack-packstack-0:2013.2.1-0.33.dev1048.el6ost | * |