← Back

Puppet Tripleo

puppet-tripleo

Vendor: Openstack • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Openstack
Redhat
2Openstack
Puppet Tripleo
Nov 21, 2024
Apr 24, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious use...Show more
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.Show less