slackhq/nebula

slackhq/nebula

Releases27
Frequency2 months 3 weeks
Last Release
Stars17.5K
A scalable overlay networking tool with a focus on performance, simplicity and security

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
>= 1.7.0, < 1.10.38.1 HIGH

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of the certificate with a different fingerprint. This issue has been patched in version 1.10.3.

4.9 MEDIUM

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

<= 1.1.08.8 HIGH8.5 HIGH

Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistence or to bypass security controls. NOTE: the vendor states that this "requires a high degree of access and other preconditions that are tough to achieve."