Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-55748

Опубликовано: 17 июн. 2026
Источник: debian
EPSS Низкий

Описание

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
horizonfixed3:25.7.3-2package
horizonfixed3:25.3.0-3+deb13u1trixiepackage
horizonfixed3:23.0.0-5+deb12u2bookwormpackage
horizonpostponedbullseyepackage

Примечания

  • https://wiki.openstack.org/wiki/OSSN/OSSN-0097

  • https://launchpad.net/bugs/2152240

EPSS

Процентиль: 12%
0.00218
Низкий

Связанные уязвимости

CVSS3: 6
ubuntu
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

CVSS3: 6
redhat
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

CVSS3: 6
nvd
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

CVSS3: 6
github
около 2 месяцев назад

OpenStack Horizon RC file generation does not escape special characters in project names

EPSS

Процентиль: 12%
0.00218
Низкий