Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55748

Опубликовано: 17 июн. 2026
Источник: redhat
CVSS3: 6
EPSS Низкий

Описание

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

A flaw was found in OpenStack Horizon. This vulnerability allows a highly privileged remote attacker, with user interaction, to craft a project name containing shell metacharacters. When scripts for OpenStack RC file downloading are produced, these metacharacters may be processed, potentially leading to information disclosure or integrity compromise. This issue is considered by some as a security hardening opportunity rather than a direct vulnerability.

Отчет

This Moderate impact flaw in OpenStack Horizon on Red Hat OpenStack Platform allows a highly privileged remote attacker to potentially achieve information disclosure or integrity compromise. Exploitation requires user interaction and the ability to craft project names with shell metacharacters, which are then processed during the generation of OpenStack RC files. The specific conditions and high privileges required limit the overall risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-horizonFix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-horizonFix deferred
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-horizonFix deferred
Red Hat OpenStack Platform 18.0rhoso/openstack-horizon-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2489863OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters

EPSS

Процентиль: 9%
0.0019
Низкий

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

CVSS3: 6
nvd
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

CVSS3: 6
debian
около 2 месяцев назад

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file ...

CVSS3: 6
github
около 2 месяцев назад

OpenStack Horizon RC file generation does not escape special characters in project names

EPSS

Процентиль: 9%
0.0019
Низкий

6 Medium

CVSS3