Логотип exploitDog
bind:CVE-2026-28370
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-28370

Количество 4

Количество 4

ubuntu логотип

CVE-2026-28370

около 1 месяца назад

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-28370

около 1 месяца назад

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-28370

около 1 месяца назад

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0 ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-8xwf-cr4r-856r

около 1 месяца назад

OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-28370

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-28370

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-28370

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0 ...

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-8xwf-cr4r-856r

OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection

CVSS3: 9.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу