PT-2014-3696 · Crowbar · Barclamp
Publicado
2014-04-04
·
Atualizado
2014-04-04
·
CVE-2014-0592
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Barclamp (aka barclamp-network) version 1.7
Description
The issue allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs, because netfilter is not enabled on bridges when creating new instances.
Recommendations
For Barclamp (aka barclamp-network) version 1.7, enable netfilter on bridges when creating new instances to prevent bypassing security group restrictions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Barclamp