CyberRota Analysis
AI-GeneratedOpenStack Octavia versions prior to 18.0.1 are vulnerable due to the Amphora provider driver failing to validate the listener and pool tls_ciphers fields, allowing authenticated users to inject arbitrary HAProxy configuration directives. This critical vulnerability can lead to unauthorized control over load balancer configurations, potentially compromising the security of the entire deployment. Organizations using the Amphora provider for TLS-enabled load balancers should prioritize immediate updates to mitigate this risk.
Original NVD Description
In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and thus an authenticated project member who owns a TLS-enabled load balancer can embed a newline and inject arbitrary HAProxy configuration directives. Only deployments using the Amphora provider are affected.