Vulnerability CVE-2016-7404


Published: 2019-06-21

Description:
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Openstack -> Magnum 

 References:
https://bugs.launchpad.net/magnum/+bug/1620536
https://bugzilla.suse.com/show_bug.cgi?id=998182
https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22
https://www.securityfocus.com/bid/98467

Copyright 2020, cxsecurity.com

 

Back to Top