CVE-2016-7404 Information
Feb 14, 2021
cve
Description
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances’ SSL certificates they allow full API access though and can be used to perform any API operation the user is authorized to perform.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://bugs.launchpad.net/magnum/+bug/1620536 https://bugzilla.suse.com/show_bug.cgi?id=998182 https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22 https://www.securityfocus.com/bid/98467
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: