The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-2893 | The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command. |
![]() |
GHSA-72p9-6gc7-q93r | OpenStack Neutron Improper Authentication vulnerability |
![]() |
USN-2194-1 | OpenStack Neutron vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:37.915Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0056

No data.

Status : Deferred
Published: 2014-05-08T14:29:12.737
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0056


No data.