Insecure HTTP Retrieval in OpenStack RabbitMQ Container Image
CVE-2018-14620
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 September 2018
What is CVE-2018-14620?
The OpenStack RabbitMQ container image has a vulnerability that arises from its insecure retrieval of the rabbitmq_clusterer component over HTTP during the build process. This flaw enables an attacker to serve malicious code to the image builder, potentially leading to the installation of compromised software within the resultant container image. Versions of openstack-rabbitmq-container and openstack-containers distributed with Red Hat OpenStack releases 12, 13, and 14 are identified as susceptible to this security issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openstack-rabbitmq-container 12, 13, 14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved