Количество 4
Количество 4
CVE-2026-40213
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
CVE-2026-40213
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
CVE-2026-40213
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the ...
GHSA-mm7j-mhhj-hj36
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40213 OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC. | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40213 OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC. | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40213 OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the ... | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
GHSA-mm7j-mhhj-hj36 OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints | CVSS3: 7.4 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу