Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in OpenStack Octavia's Amphora provider driver, which fails to properly validate specific configuration fields for TLS-enabled load balancers. An authenticated user with project access could potentially inject arbitrary commands into the HAProxy configuration, impacting the security and operation of affected deployments. The main concern at this time is confirming if this specific technology is in use and exposed.
- Configuration flaw in load balancer driver.
- Matters if using OpenStack Octavia Amphora.
- Confirm relevance and exposure to Octavia.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to an OpenStack project could manipulate the TLS cipher settings of a load balancer. This involves crafting a malicious input for the `tls_ciphers` field, which is then written directly into the HAProxy configuration. The vulnerability allows for the injection of arbitrary HAProxy directives, potentially leading to significant compromise. This specific vulnerability affects deployments utilizing the Amphora provider.
- Authenticated project member is required.
- Malicious input in listener/pool TLS ciphers.
- Arbitrary HAProxy configuration injection.
Live Threat
Current exploitation, exposure, and threat context
In deployments using the OpenStack Octavia Amphora provider, an authenticated project member could inject arbitrary HAProxy configuration directives by embedding control characters into listener or pool TLS cipher fields. This could occur when the system generates HAProxy configurations for TLS-enabled load balancers.
- Arbitrary HAProxy configuration.
- Control characters in TLS cipher fields.
- Unrestricted service configuration changes.
Operational Fix
Recommended remediation, mitigation, and detection steps
Deployments using the OpenStack Octavia Amphora provider driver are affected by this vulnerability. Owners of TLS-enabled load balancers within a project are responsible for assessing their exposure. The initial step involves identifying all instances of the Amphora provider, determining their network reachability and business criticality, and then confirming the accountable project member to plan remediation.
- Identify Amphora provider instances.
- Verify TLS-enabled load balancer reachability.
- Plan remediation with accountable owners.