{"id":"CVE-2019-17134","aliases":["GHSA-r4v4-3jj7-jc29","PYSEC-2026-433"],"url":"https://o3.security/vulnerability/CVE-2019-17134","summary":"OpenStack Octavia Amphora-Agent not requiring Client-Certificate","details":"Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.","published":"2019-10-08T18:15:14.153Z","modified":"2026-07-08T05:53:16.297413244Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.02296,"percentile":0.81801,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"octavia","fixedVersion":"2.1.2"},{"ecosystem":"PyPI","name":"octavia","fixedVersion":"3.2.0"},{"ecosystem":"PyPI","name":"octavia","fixedVersion":"4.1.0"}],"fix":null,"references":[{"type":"WEB","url":"https://storyboard.openstack.org/#%21/story/2006660"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3743"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3788"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0721"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4153-1/"},{"type":"FIX","url":"https://review.opendev.org/686541"},{"type":"FIX","url":"https://review.opendev.org/686543"},{"type":"FIX","url":"https://review.opendev.org/686544"},{"type":"FIX","url":"https://review.opendev.org/686545"},{"type":"FIX","url":"https://review.opendev.org/686546"},{"type":"FIX","url":"https://review.opendev.org/686547"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2019-005.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:53:16.297413244Z"}}