OSSA-2015-018: Neutron firewall rules bypass through port update

OSSA-2015-018: Neutron firewall rules bypass through port update

Date:September 08, 2015
CVE:CVE-2015-5240

Affects

  • Neutron: versions through 2014.2.3 and 2015.1 versions through 2015.1.1

Description

Kevin Benton from Mirantis reported a vulnerability in Neutron. By changing the device owner of an instance’s port right after it is created, an authenticated user may prevent application of firewall rules and so avoid IP anti-spoofing controls. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected.

Credits

  • Kevin Benton from Mirantis (CVE-2015-5240)

Notes

  • This fix will be included in future 2014.2.4 (juno) and 2015.1.2 (kilo) releases.
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.