CVE-2016-9599
24.04.2018, 01:29
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | puppet-tripleo | 5.5.0 |
openstack | puppet-tripleo | 6.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration