An authenticated user who owns a load balancer managed by Octavia's Amphora provider can exploit the affected API fields. The issue applies to HAProxy configurations generated on the provider-managed amphora.
Exploitation can allow arbitrary commands to run as root on the provider-managed amphora. It can also disclose other tenants' TLS private keys and certificates, the deployment heartbeat key stored on the amphora, and provide reachability to the amphora's control-plane network.
The affected fields are listener and pool tls_ciphers, plus L7 policy redirect_url and redirect_prefix. Control characters in these values were not rejected before the values were written into generated HAProxy configuration.
Affected versions are Octavia versions from 0.8.0 up to, but not including, 16.1.0, as well as 17.0.0 and 18.0.0.