Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0056

Опубликовано: 08 мая 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1

Описание

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

РелизСтатусПримечание
devel

not-affected

1:2014.1~b3-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1:2014.1~b3-0ubuntu1]]
lucid

DNE

precise

DNE

quantal

DNE

saucy

released

1:2013.2.3-0ubuntu1.1
trusty

not-affected

1:2014.1~b3-0ubuntu1
trusty/esm

DNE

trusty was not-affected [1:2014.1~b3-0ubuntu1]
upstream

released

2013.2.3

Показывать по

EPSS

Процентиль: 44%
0.00216
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

nvd
больше 11 лет назад

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

debian
больше 11 лет назад

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not chec ...

github
больше 3 лет назад

OpenStack Neutron Improper Authentication vulnerability

EPSS

Процентиль: 44%
0.00216
Низкий

2.1 Low

CVSS2