Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:LDefault status
unaffected
Any version before 1.9.7
affected
Description
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Problem types
CWE-420 Unprotected Alternate Channel
Product status
Any version before 1.9.7
References
github.com/slackhq/nebula/pull/1493
github.com/slackhq/nebula/pull/1494
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.