CVE-2018-14620
published 2018-09-10CVE-2018-14620: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.60%
44.4th percentile
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | openstack-rabbitmq-container | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
vendor_redhat·2018-09-10·CVSS 4.7
CVE-2018-14620 [MEDIUM] CWE-494 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP, without validation, during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image.
Package: openstack-rabbitmq
GHSA
GHSA-w9j2-jxm7-7f2v: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage
ghsa_unreviewed·2022-05-13
CVE-2018-14620 [CRITICAL] CWE-20 GHSA-w9j2-jxm7-7f2v: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.
No detection rules found.
No public exploits indexed.
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
Bugzilla
CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
bugzilla·2018-09-10·CVSS 4.7
CVE-2018-14620 [MEDIUM] CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build
The openstack-rabbitmq-container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image.
Discussion:
This issue has been addressed in the following products:
Red Hat OpenStack Platform 13.0 (Queens)
Via RHSA-2018:2721 https://access.redhat.com/errata/RHSA-2018:2721
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 12.0 (Pike)
Via RHSA-2018:2729 https://access.redhat.com/errata/RHSA-2018:2729
https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:2729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14620https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:2729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14620
2018-09-10
Published