OpenStack Platform Vulnerability Exposes Containers to MITM Attacks
CVE-2024-8007
8.1HIGH
Key Information
- Vendor
- Red Hat
- Status
- Red Hat Openstack Platform 16.1
- Red Hat Openstack Platform 16.2
- Red Hat Openstack Platform 17.1
- Vendor
- CVE Published:
- 21 August 2024
Summary
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 7.5 - (HIGH)
Vulnerability published.
Vulnerability Reserved.
Reported to Red Hat.
Collectors
NVD DatabaseMitre Database