CVE-2016-9599: High severity openstack tripleo vulnerability
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9599?
CVE-2016-9599 is considered to have a high severity due to its potential for exposing unauthorized resources through improperly configured IPtables rules.
How do I fix CVE-2016-9599?
To fix CVE-2016-9599, upgrade puppet-tripleo to version 5.5.0 or later, or 6.2.0 or later to ensure proper IPtables management and access control.
Which versions of puppet-tripleo are affected by CVE-2016-9599?
Versions of puppet-tripleo before 5.5.0 and 6.2.0 are affected by CVE-2016-9599.
Can CVE-2016-9599 affect SSL configurations?
Yes, if SSL is enabled, CVE-2016-9599 can allow malicious users to exploit open ports to access unauthorized resources.
What type of vulnerability is CVE-2016-9599?
CVE-2016-9599 is an access-control vulnerability related to IPtables rules management.