HIGH🇵🇱 Wersja polska

CVE-2024-8007

CVSS 8.1v3.1pub. 2024-08-21upd. 2024-11-25

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Openstack Platform

    APP
    Redhat
    16.116.217.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2020-10731CRITICAL9.9PL ✓same product

Brak SELinux w kontenerze nova_libvirt w Red Hat OpenStack Platform 16

CVE-2023-1625HIGH7.4same product

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker ...

CVE-2022-3596HIGH7.5same product

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to...

CVE-2023-1108HIGH7.5same product

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected han...

CVE-2023-3354HIGH7.5same product

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whethe...