Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-9735

Опубликовано: 13 мар. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

РелизСтатусПримечание
bionic

released

2:12.0.6-0ubuntu1
cosmic

released

2:13.0.2-0ubuntu3.4
devel

not-affected

2:14.0.0~b1~git2018120609.2e720b158b-0ubuntu2
disco

not-affected

2:14.0.0~b1~git2018120609.2e720b158b-0ubuntu2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra/bionic

released

2:12.0.6-0ubuntu1
esm-infra/xenial

released

2:8.4.0-0ubuntu7.4
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was needs-triage

Показывать по

EPSS

Процентиль: 83%
0.01965
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

CVSS3: 6.5
nvd
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

CVSS3: 6.5
debian
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack N ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Neutron's unsupported dport option prevents applying security groups

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость драйвера групп безопасности iptables компонента Neutron SDN-платформы OpenStack, связанная с некорректной обработкой групповых настроек безопасности, позволяющая нарушителю обойти заданные правила политики безопасности

EPSS

Процентиль: 83%
0.01965
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3