First published: Wed Mar 03 2021(Updated: )
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | <16.3.3 | |
OpenStack Neutron | >=17.0.0<17.1.3 | |
OpenStack Neutron | =18.0.0 | |
Redhat Openstack Platform | =10.0 | |
Redhat Openstack Platform | =13.0 | |
Redhat Openstack Platform | =16.1 | |
Redhat Openstack Platform | =16.2 | |
pip/neutron | >=17.0.0<17.1.1 | 17.1.1 |
pip/neutron | <15.3.3 | 15.3.3 |
pip/neutron | >=16.0.0<16.3.1 | 16.3.1 |
redhat/neutron | <15.3.3 | 15.3.3 |
redhat/neutron | <16.3.1 | 16.3.1 |
redhat/neutron | <17.1.1 | 17.1.1 |
<16.3.3 | ||
>=17.0.0<17.1.3 | ||
=18.0.0 | ||
=10.0 | ||
=13.0 | ||
=16.1 | ||
=16.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20267 is a vulnerability in openstack-neutron's default Open vSwitch firewall rules.
The vulnerability can be exploited by sending carefully crafted packets to impersonate the IPv6 addresses of other systems on the network.
CVE-2021-20267 has a severity score of 7.1, which is considered high.
OpenStack Neutron versions up to and including 16.3.3, versions between 17.0.0 and 17.1.3, and version 18.0.0 are affected. Red Hat Openstack Platform versions 10.0, 13.0, 16.1, and 16.2 are also affected.
To fix CVE-2021-20267, update to OpenStack Neutron version 16.3.3, versions between 17.0.0 and 17.1.3, or version 18.0.0. For Red Hat Openstack Platform, update to versions 10.0, 13.0, 16.1, or 16.2.