OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenstack Magnum
APPOpenstackall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2024-28718CRITICAL9.8PL ✓same product
RCE w OpenStack Magnum — podatność w komponencie cert_manager.py
CVE-2026-28370CRITICAL9.1PL ✓same vendor
RCE w OpenStack Vitrage — wykonanie kodu przez parser zapytań API
CVE-2021-38598CRITICAL9.1PL ✓same vendor
OpenStack Neutron — podszywanie pod adresy sprzętowe via linuxbridge/ebtables-nft
CVE-2020-26943CRITICAL9.9PL ✓same vendor
OpenStack Blazar-Dashboard: RCE przez niebezpieczne użycie eval()
CVE-2013-2166CRITICAL9.8PL ✓same vendor
Obejście szyfrowania middleware memcache w python-keystoneclient