Incomplete Fix for CVE-2021-44716 in Red Hat OpenStack Platform
CVE-2024-4437
7.5HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 8 May 2024
Summary
The etcd package included with the Red Hat OpenStack platform has an incomplete resolution to a previously identified vulnerability, CVE-2021-44716. This situation arises from the utilization of the standard library from golang.org rather than the version provided specifically by Red Hat Enterprise Linux. It is critical to compile the etcd package with the appropriate library to mitigate potential security risks associated with this oversight.
Affected Version(s)
Red Hat OpenStack Platform 16.1 0:3.3.23-16.el8ost
Red Hat OpenStack Platform 16.2 0:3.3.23-16.el8ost
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database