github.com/slackhq/nebula is vulnerable to Improper Certificate Validation
60
Medium Risk
Affected versions of this package are vulnerable to IP-spoofing due to improper CIDR construction in hostmap.go. When a node’s certificate contains multiple IPs or a routed subnet, the code incorrectly expands the allowed addresses (using Mask.Size() instead of the address bit length), letting a compromised or rogue node send packets with any source IP from the Nebula network that peers will accept. An attacker who controls such a node can impersonate other hosts, inject arbitrary UDP traffic, or disrupt connections (for example by sending forged TCP RSTs).
You are affected if you are using a version that falls within the vulnerable range.
github.com/slackhq/nebula is vulnerable to Improper Certificate Validation in versions 1.9.4 - 1.9.6.
Upgrade the github.com/slackhq/nebula library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant