puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "5.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "6.2.0"
}
]
}