CVE-2016-9599
published 2018-04-24CVE-2016-9599: puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP…
PriorityP341high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
0.85%
54.0th percentile
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | puppet-tripleo | — | — |
| openstack | puppet-tripleo | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f29f-jrc4-qmh5: puppet-tripleo before versions 5
ghsa_unreviewed·2022-05-13
CVE-2016-9599 [HIGH] CWE-284 GHSA-f29f-jrc4-qmh5: puppet-tripleo before versions 5
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
Red Hat
puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
vendor_redhat·2016-12-22·CVSS 7.1
CVE-2016-9599 [HIGH] CWE-284 puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
An access-control flaw was discovered in puppet-tripleo's IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. Some API services in Red Hat OpenStack Platform director are not exposed to public networks, which meant their $public_ssl_port value was set to empty (for example, openstack-glance, which is deployed by default on both undercloud and overcloud). If SSL was enabled, a m
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9599 puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
bugzilla·2017-01-03·CVSS 7.1
CVE-2016-9599 [HIGH] CVE-2016-9599 puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
CVE-2016-9599 puppet-tripleo: if ssl is enabled, traffic is open on both undercloud and overcloud
Puppet IPtables rules management allows the creation of TCP / UDP rules with empty port value.Some API services in Director are not exposed to public networks,
which means $public_ssl_port are empty for some services (for example,
Glance, which is deployed by default on both undercloud and overcloud).
If SSL is enabled, several IPtables rules are created without a
port specified, which opens all traffic for TCP protocol. Example
of rule:
-A INPUT -p tcp -m comment --comment "100 glance_registry_haproxy_ssl"
-m state --state NEW -j ACCEPT
Discussion:
Created puppet-tripleo tracking bugs for this issue:
Affects: openstack-rdo [bug 1409689]
---
Acknowledgments:
Name: Ben Nemec (Red Hat)
Bugzilla
CVE-2016-9599 puppet-tripleo:if ssl is enabled, traffic is open on both undercloud and overcloud [openstack-rdo]
bugzilla·2017-01-03·CVSS 7.1
CVE-2016-9599 [HIGH] CVE-2016-9599 puppet-tripleo:if ssl is enabled, traffic is open on both undercloud and overcloud [openstack-rdo]
CVE-2016-9599 puppet-tripleo:if ssl is enabled, traffic is open on both undercloud and overcloud [openstack-rdo]
This as an RDO Project security tracking bug against puppet-tripleo. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
2018-04-24
Published