OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Packstack | Redhat | 2012.2.1 (including) | 2012.2.1 (including) |
| OpenStack 4 for RHEL 6 | RedHat | openstack-packstack-0:2013.2.1-0.33.dev1048.el6ost | * |