Openstack Neutron has Insufficient Verification of IPv6 addresses
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Package
Affected versions
>= 16.0.0, < 16.3.1
< 15.3.3
>= 17.0.0, < 17.1.1
Patched versions
16.3.1
15.3.3
17.1.1
Description
Published by the National Vulnerability Database
May 28, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Feb 23, 2024
Last updated
Sep 26, 2024
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
References