CVE-2018-14620Download of Code Without Integrity Check in RED HAT Openstack-rabbitmq-container

Severity
9.8CRITICALNVD
CNA4.7
EPSS
0.1%
top 68.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateMay 13

Description

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDredhat/openstack12, 13+1

🔴Vulnerability Details

2
GHSA
GHSA-w9j2-jxm7-7f2v: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage2022-05-13
CVEList
CVE-2018-14620: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage2018-09-10

📋Vendor Advisories

1
Red Hat
openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build2018-09-10

💬Community

1
Bugzilla
CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build2018-09-10
CVE-2018-14620 — RED vulnerability | cvebase