CVE-2014-0056
Publication date 1 April 2014
Last updated 24 July 2024
Ubuntu priority
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Status
Package | Ubuntu Release | Status |
---|---|---|
neutron | 14.04 LTS trusty | Not in release |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2194-1
- OpenStack Neutron vulnerability
- 5 May 2014