Description
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
Problem types
CWE-420 Unprotected Alternate Channel
Product status
Any version before 1.9.7
References
github.com/slackhq/nebula/pull/1493
github.com/slackhq/nebula/pull/1494