USN-4153-1: Octavia vulnerability
Daniel Preussker discovered that Octavia incorrectly handled client certificate checking. A remote attacker on the management network could possibly use this issue to perform configuration changes and obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4153-1?
USN-4153-1 is classified as a high severity vulnerability due to improper handling of client certificate checking.
How do I fix USN-4153-1?
To fix USN-4153-1, upgrade the affected packages to version 4.0.0-0ubuntu1.2 or later.
What systems are affected by USN-4153-1?
USN-4153-1 affects Ubuntu 19.04 installations running octavia-common, python3-octavia, and amphora-agent packages.
What kind of attack can exploit USN-4153-1?
A remote attacker on the management network could exploit USN-4153-1 to perform unauthorized configuration changes and access sensitive information.
Who discovered the vulnerability USN-4153-1?
The vulnerability USN-4153-1 was discovered by researcher Daniel Preussker.