Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10731

Опубликовано: 28 июл. 2020
Источник: redhat
CVSS3: 9.9
EPSS Низкий

Описание

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)openstack-tripleo-heat-templatesNot affected
Red Hat OpenStack Platform 13 (Queens)openstack-tripleo-heat-templatesNot affected
Red Hat OpenStack Platform 15.0 (Stein)openstack-tripleo-heat-templatesFixedRHSA-2020:341011.08.2020
Red Hat OpenStack Platform 15.0 (Stein)python-paunchFixedRHSA-2020:341011.08.2020
Red Hat OpenStack Platform 16.0 (Train)openstack-tripleo-heat-templatesFixedRHSA-2020:340611.08.2020
Red Hat OpenStack Platform 16.0 (Train)python-paunchFixedRHSA-2020:340611.08.2020
Red Hat OpenStack Platform 16.1openstack-tripleo-heat-templatesFixedRHSA-2020:319929.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284->CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=1831544openstack-tripleo-heat-templates: No sVirt protection for OSP16 VMs due to disabled SELinux

EPSS

Процентиль: 51%
0.00281
Низкий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
больше 5 лет назад

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.

CVSS3: 9.9
github
больше 3 лет назад

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.

EPSS

Процентиль: 51%
0.00281
Низкий

9.9 Critical

CVSS3