Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7404

Опубликовано: 21 июн. 2019
Источник: debian
EPSS Низкий

Описание

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
magnumfixed3.1.1-5package

Примечания

  • https://git.openstack.org/cgit/openstack/magnum/commit/?id=0bb0d6486d6771ee21bbf897a091b1aa59e01b22

EPSS

Процентиль: 86%
0.02859
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

CVSS3: 9.8
nvd
больше 6 лет назад

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

CVSS3: 9.8
github
больше 3 лет назад

Openstack Magnum Unsafe Credential Handling

EPSS

Процентиль: 86%
0.02859
Низкий