OpenStack Platform Vulnerability Exposes Containers to MITM Attacks

CVE-2024-8007
8.1HIGH

Key Information

Vendor
Red Hat
Status
Red Hat Openstack Platform 16.1
Red Hat Openstack Platform 16.2
Red Hat Openstack Platform 17.1
Vendor
CVE Published:
21 August 2024

Summary

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: null to: 7.5 - (HIGH)

  • Vulnerability published.

  • Vulnerability Reserved.

  • Reported to Red Hat.

Collectors

NVD DatabaseMitre Database
.