CVE-2019-10876
openstack-neutron: DOS via broken port range merging in security group
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Se ha descubierto un problema en OpenStack Neutron, en las versiones 11.x anteriores a la 11.0.7, en las 12.x anteriores a la 12.0.6 y en las 13.x anteriores a la 13.0.3. Al crear dos grupos de seguridad con rangos de puertos separados/solapados, un usuario autenticado podría impedir que Neutron sea capaz de configurar las redes en cualquier nodo de cálculo donde se encuentran dichos grupos de seguridad, debido a un error de claves en el firewall de Open vSwitch (OVS). Se han visto afectados todos los despliegues de Neutron que utilizan neutron-openvswitch-agent.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-04 CVE Reserved
- 2019-04-05 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2019/04/09/2 | Mailing List | |
https://bugs.launchpad.net/ossa/+bug/1813007 | Issue Tracking | |
https://security.openstack.org/ossa/OSSA-2019-002.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:0879 | 2021-08-04 | |
https://access.redhat.com/errata/RHSA-2019:0935 | 2021-08-04 | |
https://review.openstack.org/#/q/topic:bug/1813007 | 2021-08-04 | |
https://access.redhat.com/security/cve/CVE-2019-10876 | 2019-04-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1695883 | 2019-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 11.0.0 < 11.0.7 Search vendor "Openstack" for product "Neutron" and version " >= 11.0.0 < 11.0.7" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 12.0.0 < 12.0.6 Search vendor "Openstack" for product "Neutron" and version " >= 12.0.0 < 12.0.6" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 13.0.0 < 13.0.3 Search vendor "Openstack" for product "Neutron" and version " >= 13.0.0 < 13.0.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 13 Search vendor "Redhat" for product "Openstack" and version "13" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 14 Search vendor "Redhat" for product "Openstack" and version "14" | - |
Affected
|