CVE-2014-0056
low
CVSS v3
—
CVSS v2
2.1
VIR risk
2.1
Description
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0056
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| ubuntu | 13.10 | affected | |
| debian | bookworm | fixed | 2013.2.2-4 |
| debian | bullseye | fixed | 2013.2.2-4 |
| debian | forky | fixed | 2013.2.2-4 |
| debian | sid | fixed | 2013.2.2-4 |
| debian | trixie | fixed | 2013.2.2-4 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | neutron | >=2012.2,<2013.2.3 | 2013.2.3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openstack | neutron | 2012.2 | |
| openstack | neutron | 2012.2.1 | |
| openstack | neutron | 2012.2.2 | |
| openstack | neutron | 2012.2.3 | |
| openstack | neutron | 2012.2.4 | |
| openstack | neutron | 2013.1 | |
| openstack | neutron | 2013.1.1 | |
| openstack | neutron | 2013.1.2 | |
| openstack | neutron | 2013.1.3 | |
| openstack | neutron | 2013.1.4 | |
| openstack | neutron | 2013.1.5 | |
| openstack | neutron | 2013.2 | |
| openstack | neutron | 2013.2.1 | |
| openstack | neutron | 2013.2.2 | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-0056
- https://access.redhat.com/errata/RHSA-2014:0516
- https://access.redhat.com/security/cve/CVE-2014-0056
- https://bugs.launchpad.net/neutron/+bug/1243327
- https://bugzilla.redhat.com/show_bug.cgi?id=1063141
- https://opendev.org/openstack/neutron
- http://rhn.redhat.com/errata/RHSA-2014-0516.html
- http://www.openwall.com/lists/oss-security/2014/03/27/5
- http://www.ubuntu.com/usn/USN-2194-1
- https://security-tracker.debian.org/tracker/CVE-2014-0056
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.