CVE-2019-9735
openstack-neutron: incorrect validation of port settings in iptables security group driver
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)
Se ha detectado un fallo en el módulo de firewall iptables en OpenStack Neutron en versiones anteriores a la 10.0.8, en las 11.x anteriores a la 11.0.7, en las 12.x anteriores a la 12.0.6 y en las 13.x anteriores a la 13.0.3. Al establecer un puerto de destino en una regla de grupo de seguridad, junto con un protocolo que no soporta dicha opción (p.ej., VRRP), un usuario autenticado podría bloquear la mayor aplicación de esas reglas de grupo de seguridad para instancias desde cualquier project/tenant en los hosts de computación a los cuales se aplican. (Solamente despliegues que empleen el grupo de seguridad iptables se ven afectados.)
A validation flaw was discovered in the iptables firewall module in OpenStack Neutron. By setting a destination port in a security group rule, along with a protocol that does not support that option (for example, VRRP), an authenticated user could block further application of security group rules for instances from any project or tenant on the compute hosts to which it's applied. Only OpenStack deployments that use the iptables security group driver are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-12 CVE Reserved
- 2019-03-13 CVE Published
- 2024-08-03 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2019/03/18/2 | Mailing List | |
http://www.securityfocus.com/bid/107390 | Third Party Advisory | |
https://seclists.org/bugtraq/2019/Mar/24 | Mailing List |
URL | Date | SRC |
---|---|---|
https://launchpad.net/bugs/1818385 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://security.openstack.org/ossa/OSSA-2019-001.html | 2021-08-04 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:0879 | 2021-08-04 | |
https://access.redhat.com/errata/RHSA-2019:0916 | 2021-08-04 | |
https://access.redhat.com/errata/RHSA-2019:0935 | 2021-08-04 | |
https://usn.ubuntu.com/4036-1 | 2021-08-04 | |
https://www.debian.org/security/2019/dsa-4409 | 2021-08-04 | |
https://access.redhat.com/security/cve/CVE-2019-9735 | 2019-04-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1690745 | 2019-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | < 10.0.8 Search vendor "Openstack" for product "Neutron" and version " < 10.0.8" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 11.0.0 < 11.0.7 Search vendor "Openstack" for product "Neutron" and version " >= 11.0.0 < 11.0.7" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 12.0.0 < 12.0.6 Search vendor "Openstack" for product "Neutron" and version " >= 12.0.0 < 12.0.6" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Neutron Search vendor "Openstack" for product "Neutron" | >= 13.0.0 < 13.0.3 Search vendor "Openstack" for product "Neutron" and version " >= 13.0.0 < 13.0.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 10 Search vendor "Redhat" for product "Openstack" and version "10" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 13 Search vendor "Redhat" for product "Openstack" and version "13" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 14 Search vendor "Redhat" for product "Openstack" and version "14" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|