An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
References
| Link | Resource |
|---|---|
| https://bugs.launchpad.net/magnum/+bug/2047690 | Exploit Issue Tracking Patch |
| https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f | Third Party Advisory |
| https://review.opendev.org/c/openstack/magnum/+/907305 | Patch |
| https://bugs.launchpad.net/magnum/+bug/2047690 | Exploit Issue Tracking Patch |
| https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f | Third Party Advisory |
| https://review.opendev.org/c/openstack/magnum/+/907305 | Patch |
Configurations
History
No history.
Information
Published : 2024-04-12 13:15
Updated : 2025-06-17 21:00
NVD link : CVE-2024-28718
Mitre link : CVE-2024-28718
CVE.ORG link : CVE-2024-28718
JSON object : View
Products Affected
openstack
- magnum
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
