668
VMScore

CVE-2016-7404

Published: 21/06/2019 Updated: 26/06/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack magnum -

Vendor Advisories

Debian Bug report logs - #863547 CVE-2016-7404 Package: src:magnum; Maintainer for src:magnum is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 28 May 2017 11:45:01 UTC Severity: grave Tags: security Fixed in version magnum/311-5 Done: Ondřej Nov ...