CVE-2019-17134: Critical severity opendev Octavia Openstack vulnerability
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn certreqs option is True but is supposed to be ssl.CERTREQUIRED.
Other sources
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn certreqs option is True but is supposed to be ssl.CERTREQUIRED.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/octaviato a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
pip/octaviato a version that resolves this vulnerability.Fixed in 3.2.0 - Upgrade
Upgrade
pip/octaviato a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
debian/octaviato a version that resolves this vulnerability.Fixed in 7.1.0-2Fixed in 11.0.0-2Fixed in 16.0.0-2Fixed in 17.0.0-5 - Upgrade
Upgrade
redhat/openstack-octaviato a version that resolves this vulnerability.Fixed in 2.1.2-1.el7 - Upgrade
Upgrade
redhat/openstack-octavia-4.1.0to a version that resolves this vulnerability.Fixed in 1 - Upgrade
Upgrade
OpenStack Octavia Amphora Imagesto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
OpenStack Octavia Amphora Imagesto a version that resolves this vulnerability.Fixed in 3.2.0 - Upgrade
Upgrade
OpenStack Octavia Amphora Imagesto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
OpenStack Octavia Amphora Imagesto a version that resolves this vulnerability.Patch OSSA-2019-005
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17134?
CVE-2019-17134 has a high severity due to its potential to allow unauthorized access to sensitive configurations and information.
How do I fix CVE-2019-17134?
To fix CVE-2019-17134, upgrade OpenStack Octavia to version 2.1.2 or later, or to a version above 3.2.0 or 4.1.0.
What software is affected by CVE-2019-17134?
CVE-2019-17134 affects OpenStack Octavia versions between 0.10.0 and 2.1.2, as well as versions from 3.0.0 to 3.2.0, and from 4.0.0 to 4.1.0.
Is there a workaround for CVE-2019-17134?
There is no documented workaround for CVE-2019-17134, and it is strongly recommended to apply updates.
What are the potential consequences of CVE-2019-17134?
The exploitation of CVE-2019-17134 can lead to unauthorized actions performed on the Octavia Agent, compromising the security of the OpenStack deployment.