Bug 1063141 - (CVE-2014-0056) CVE-2014-0056 openstack-neutron: insufficient authorization checks when creating ports
CVE-2014-0056 openstack-neutron: insufficient authorization checks when creat...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140328,repor...
: Security
Depends On: 1081861 1081862 1081863 1087664
Blocks: 1063143
  Show dependency treegraph
 
Reported: 2014-02-10 01:28 EST by Murray McAllister
Modified: 2016-04-26 19:30 EDT (History)
15 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-07-15 03:37:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
havana patch (9.98 KB, patch)
2014-05-06 01:25 EDT, Garth Mollett
no flags Details | Diff

  None (edit)
Description Murray McAllister 2014-02-10 01:28:55 EST
The OpenStack project reports:

Title: Routers can be cross plugged by other tenants
Reporter: Aaron Rosen (VMWare)
Products: Neutron
Affects: 2012.2 versions up to 2013.2.2

Description:
Aaron Rosen from VMWare reported a vulnerability where Neutron fails to
perform proper authorization checks when creating ports. By choosing a
device id of a router from a different tenant when creating a port, an
authenticated user can access the network of other tenants. This affects
deployments of Neutron using plugins relying on the l3-agent.
Comment 1 Murray McAllister 2014-02-10 01:29:51 EST
Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Aaron Rosen from VMware as the original reporter.
Comment 4 Murray McAllister 2014-03-28 02:13:00 EDT
This is public now:

http://www.openwall.com/lists/oss-security/2014/03/27/5
Comment 5 Murray McAllister 2014-03-28 02:15:15 EDT
Created openstack-neutron tracking bugs for this issue:

Affects: fedora-20 [bug 1081861]
Comment 6 Murray McAllister 2014-03-28 02:15:21 EDT
Created openstack-quantum tracking bugs for this issue:

Affects: fedora-19 [bug 1081862]
Affects: epel-6 [bug 1081863]
Comment 8 Garth Mollett 2014-05-06 01:25:06 EDT
Created attachment 892762 [details]
havana patch
Comment 9 errata-xmlrpc 2014-05-29 16:19:07 EDT
This issue has been addressed in following products:

  OpenStack 4 for RHEL 6

Via RHSA-2014:0516 https://rhn.redhat.com/errata/RHSA-2014-0516.html

Note You need to log in before you can comment on or make changes to this bug.