Title: Neutron firewall rules bypass through port update Reporter: Kevin Benton (Mirantis) Products: Neutron Affects: versions through 2014.2.3 and 2015.1 versions through 2015.1.1 Description: Kevin Benton from Mirantis reported a vulnerability in Neutron. By changing the device owner of an instance's port right after it is created, an authenticated user may prevent application of firewall rules and so avoid IP anti-spoofing controls. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected. Reproducible: Always
arches, please stablize the following =sys-cluster/neutron-2015.1.1-r1
amd64 stable
x86 stable. Maintainer(s), please cleanup.
maintainer cleaned up
Maintainer(s), Thank you for you for cleanup. GLSA Vote: No
GLSA Vote: No