Missing Authorization in openstack-neutron - CVE-2021-38598
Published: October 12, 2021
openstack-neutron
Openstack
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing authorization when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. A remote attacker in control of a server instance connected to the virtual switch can send specially crafted packets to impersonate the hardware addresses of other systems on the network.