Incomplete Fix for CVE-2021-44716 in Red Hat OpenStack Platform
CVE-2024-4437

7.5HIGH

Summary

The etcd package included with the Red Hat OpenStack platform has an incomplete resolution to a previously identified vulnerability, CVE-2021-44716. This situation arises from the utilization of the standard library from golang.org rather than the version provided specifically by Red Hat Enterprise Linux. It is critical to compile the etcd package with the appropriate library to mitigate potential security risks associated with this oversight.

Affected Version(s)

Red Hat OpenStack Platform 16.1 0:3.3.23-16.el8ost

Red Hat OpenStack Platform 16.2 0:3.3.23-16.el8ost

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.