An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/magnum/+bug/2047690 | Exploit Issue Tracking Patch |
https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f | Third Party Advisory |
https://review.opendev.org/c/openstack/magnum/+/907305 | Patch |
https://bugs.launchpad.net/magnum/+bug/2047690 | Exploit Issue Tracking Patch |
https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f | Third Party Advisory |
https://review.opendev.org/c/openstack/magnum/+/907305 | Patch |
Configurations
History
17 Jun 2025, 21:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.launchpad.net/magnum/+bug/2047690 - Exploit, Issue Tracking, Patch | |
References | () https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f - Third Party Advisory | |
References | () https://review.opendev.org/c/openstack/magnum/+/907305 - Patch | |
First Time |
Openstack
Openstack magnum |
|
CPE | cpe:2.3:a:openstack:magnum:-:*:*:*:*:*:*:* |
21 Nov 2024, 09:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.launchpad.net/magnum/+bug/2047690 - | |
References | () https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f - | |
References | () https://review.opendev.org/c/openstack/magnum/+/907305 - |
15 Aug 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-367 |
12 Apr 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-12 13:15
Updated : 2025-06-17 21:00
NVD link : CVE-2024-28718
Mitre link : CVE-2024-28718
CVE.ORG link : CVE-2024-28718
JSON object : View
Products Affected
openstack
- magnum
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition