CVE-2014-0071

PackStack in Red Hat OpenStack 4.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66001
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0233.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1064163

Scores

EPSS 0.0182
EPSS Percentile 76.5%

Details

CWE
CWE-264
Status published
Products (1)
redhat/openstack 4.0
Published Apr 17, 2014
Tracked Since Feb 18, 2026