Vulnerability Description
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opendev | Octavia | >= 0.10.0, < 2.1.2 |
| Canonical | Ubuntu Linux | 19.04 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2019:3743
- https://access.redhat.com/errata/RHSA-2019:3788
- https://access.redhat.com/errata/RHSA-2020:0721
- https://review.opendev.org/686541Mailing ListPatchThird Party Advisory
- https://review.opendev.org/686543Mailing ListPatchThird Party Advisory
- https://review.opendev.org/686544Mailing ListPatchThird Party Advisory
- https://review.opendev.org/686545Mailing ListPatchThird Party Advisory
- https://review.opendev.org/686546Mailing ListPatchThird Party Advisory
- https://review.opendev.org/686547Mailing ListPatchThird Party Advisory
- https://security.openstack.org/ossa/OSSA-2019-005.htmlPatchVendor Advisory
- https://storyboard.openstack.org/#%21/story/2006660
- https://usn.ubuntu.com/4153-1/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3743
- https://access.redhat.com/errata/RHSA-2019:3788
- https://access.redhat.com/errata/RHSA-2020:0721
FAQ
What is CVE-2019-17134?
CVE-2019-17134 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve i...
How severe is CVE-2019-17134?
CVE-2019-17134 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17134?
Check the references section above for vendor advisories and patch information. Affected products include: Opendev Octavia, Canonical Ubuntu Linux.