slackhq/nebula

slackhq/nebula

Releases27
Frequency2 months 3 weeks
Last Release
Stars17.4K
A scalable overlay networking tool with a focus on performance, simplicity and security

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

4.9 MEDIUM

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.