octavia@2.1.1 vulnerabilities

OpenStack Octavia Scalable Load Balancer as a Service

Direct Vulnerabilities

Known vulnerabilities in the octavia package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Improper Certificate Validation

octavia is an operator-grade reference implementation for Load Balancing as a Service (LBaaS) for OpenStack.

Affected versions of this package are vulnerable to Improper Certificate Validation. This allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.

How to fix Improper Certificate Validation?

Upgrade octavia to version 2.1.2, 3.2.0, 4.1.0 or higher.

[0.10.0,2.1.2) [3.0.0,3.2.0) [4.0.0,4.1.0)