CVE-2019-10876
OpenStack Neutron overlapping security group rules prevents compute node network configuration
6.5
MEDIUM
CVSS 3.1
EPSS 1.8%
描述
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
如何修補 CVE-2019-10876
要修補 CVE-2019-10876,請將受影響套件升級到下列已修補版本。
- —升級至 2:13.0.2-15 或更新版本
- —升級至 11.0.7 或更新版本
- —升級至 12.0.6 或更新版本
CVE-2019-10876 正在被利用嗎?
低 — EPSS 為 1.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2:13.0.2-15
- >= 11.0.0, < 11.0.7
- >= 12.0.0, < 12.0.6, from 0, < 11.0.7, >= 13.0.0, < 13.0.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |