Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17134

Опубликовано: 08 окт. 2019
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

A certificate-validation error has been found in Octavia's amphora-agent, where an attacker with management-network access could bypass an amphora's client-certificate based authentication. Because the agent's HTTP server (gunicorn) had 'cert_reqs' set to 'True' instead of 'ssl.CERT_REQUIRED', information could be retrieved or configuration updated without a client certificate.

Меры по смягчению последствий

There is no mitigation for this issue, the flaw can only be resolved by applying updates.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295->CWE-200
Дефект:
CWE-471
https://bugzilla.redhat.com/show_bug.cgi?id=1761307openstack-octavia: amphora-agent not requiring client certificate

EPSS

Процентиль: 60%
0.0039
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

CVSS3: 9.1
nvd
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

CVSS3: 9.1
debian
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, > ...

CVSS3: 9.1
github
больше 3 лет назад

OpenStack Octavia Amphora-Agent not requiring Client-Certificate

CVSS3: 9.1
fstec
больше 6 лет назад

Уязвимость образов программного обеспечения Amphora балансировщика нагрузки OpenStack Octavia, позволяющая нарушителю получить доступ к защищаемой информации или выполнить произвольные команды

EPSS

Процентиль: 60%
0.0039
Низкий

6.7 Medium

CVSS3