CVE Vulnerabilities

CVE-2019-17134

Improper Authentication

Published: Oct 08, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.7 MODERATE
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
OctaviaOpendev0.10.0 (including)2.1.2 (excluding)
OctaviaOpendev3.0.0 (including)3.2.0 (excluding)
OctaviaOpendev4.0.0 (including)4.1.0 (excluding)
Red Hat OpenStack Platform 13.0 (Queens)RedHatopenstack-octavia-0:2.1.2-1.el7ost*
Red Hat OpenStack Platform 14.0 (Rocky)RedHatopenstack-octavia-0:3.1.0-3.el7ost*
Red Hat OpenStack Platform 15.0 (Stein)RedHatopenstack-octavia-0:4.1.2-0.20200114080449.5a71643.el8ost*
OctaviaUbuntudisco*
OctaviaUbuntutrusty*
OctaviaUbuntuupstream*

Potential Mitigations

References