VDB
Sign up
MEDIUM4.9

GHSA-x6fh-7qmf-69xh

Slack Nebula may accept arbitrary source IP addresses

Quick fix

GHSA-x6fh-7qmf-69xh — github.com/slackhq/nebula: upgrade to the fixed version with the command below.

go get github.com/slackhq/nebula@v1.9.7

Details

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/slackhq/nebula
Introduced in: 1.9.4Fixed in: 1.9.7
Fixgo get github.com/slackhq/nebula@v1.9.7

References