Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-17134

Опубликовано: 08 окт. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 9.1

Описание

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

5.0.0~b2~git2019073019.f80f25e8-0ubuntu1
disco

released

4.0.0-0ubuntu1.2
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

released

4.0.0-6
xenial

DNE

Показывать по

EPSS

Процентиль: 60%
0.0039
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

CVSS3: 9.1
nvd
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

CVSS3: 9.1
debian
больше 6 лет назад

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, > ...

CVSS3: 9.1
github
больше 3 лет назад

OpenStack Octavia Amphora-Agent not requiring Client-Certificate

CVSS3: 9.1
fstec
больше 6 лет назад

Уязвимость образов программного обеспечения Amphora балансировщика нагрузки OpenStack Octavia, позволяющая нарушителю получить доступ к защищаемой информации или выполнить произвольные команды

EPSS

Процентиль: 60%
0.0039
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3