Description
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/66001
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0233.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1064163
Scores
EPSS
0.0182
EPSS Percentile
76.5%
Details
CWE
CWE-264
Status
published
Products (1)
redhat/openstack
4.0
Published
Apr 17, 2014
Tracked Since
Feb 18, 2026