A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:HOpenstack Neutron
APPOpenstack18.0.0< 16.3.317.0.0 – 17.1.3 (excl.)Red Hat Openstack Platform
APPRedhat10.013.016.116.2
Related vulnerabilities
OpenStack Neutron — podszywanie pod adresy sprzętowe via linuxbridge/ebtables-nft
Brak SELinux w kontenerze nova_libvirt w Red Hat OpenStack Platform 16
OpenStack Neutron: ominięcie ochrony przed spoofingiem ICMPv6
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director....
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker ...