VDB
CVE-2019-10876
CVE-2019-10876
PUBLISHED
CVSS 6.5 MEDIUM
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
EPSS 0.62% · 70.6th percentile
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.62%
70.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| redhat | openstack | 13, 14 |
| openstack | neutron | 11.0.0, 12.0.0, 13.0.0 |
| PyPI | neutron | 13.0.0, 11.0.0, 12.0.0 |
Exploit Intelligence
- CIRCL seen: CVE-2019-10876 (circl-sighting)
- https://bugs.launchpad.net/ossa/+bug/1813007 (circl)
- https://review.openstack.org/#/q/topic:bug/1813007 (circl)
- https://security.openstack.org/ossa/OSSA-2019-002.html (circl)
- [oss-security] 20190409 [OSSA-2019-002] neutron-openvswitch-agent: Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876) (circl)
- RHSA-2019:0935 (circl)
- RHSA-2019:0879 (circl)
Timeline
- Apr 5, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://bugs.launchpad.net/ossa/+bug/1813007 url
- https://review.openstack.org/#/q/topic:bug/1813007 url
- https://security.openstack.org/ossa/OSSA-2019-002.html url
- [oss-security] 20190409 [OSSA-2019-002] neutron-openvswitch-agent: Unable to install new flows on compute nodes when having broken security group rules (CVE-2019-10876) mailing-list
- RHSA-2019:0935 vendor-advisory
- RHSA-2019:0879 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10876 advisory
- https://github.com/openstack/neutron package
- https://github.com/pypa/advisory-database/tree/main/vulns/neutron/PYSEC-2019-189.yaml url