Description
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2893 | The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command. |
Github GHSA |
GHSA-72p9-6gc7-q93r | OpenStack Neutron Improper Authentication vulnerability |
Ubuntu USN |
USN-2194-1 | OpenStack Neutron vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:37.915Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0056
No data.
Status : Modified
Published: 2014-05-08T14:29:12.737
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-0056
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN