The OpenStack project reports: Title: Routers can be cross plugged by other tenants Reporter: Aaron Rosen (VMWare) Products: Neutron Affects: 2012.2 versions up to 2013.2.2 Description: Aaron Rosen from VMWare reported a vulnerability where Neutron fails to perform proper authorization checks when creating ports. By choosing a device id of a router from a different tenant when creating a port, an authenticated user can access the network of other tenants. This affects deployments of Neutron using plugins relying on the l3-agent.
Acknowledgements: Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Aaron Rosen from VMware as the original reporter.
This is public now: http://www.openwall.com/lists/oss-security/2014/03/27/5
Created openstack-neutron tracking bugs for this issue: Affects: fedora-20 [bug 1081861]
Created openstack-quantum tracking bugs for this issue: Affects: fedora-19 [bug 1081862] Affects: epel-6 [bug 1081863]
Created attachment 892762 [details] havana patch
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0516 https://rhn.redhat.com/errata/RHSA-2014-0516.html