CVE-2024-8007
published 2024-08-21CVE-2024-8007: A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy…
PriorityP341high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.39%
31.5th percentile
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w89j-rfr2-3vwq: A flaw was found in the Red Hat OpenStack Platform (RHOSP) director
ghsa_unreviewed·2024-08-21
CVE-2024-8007 [HIGH] CWE-295 GHSA-w89j-rfr2-3vwq: A flaw was found in the Red Hat OpenStack Platform (RHOSP) director
A flaw was found in the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
Red Hat
openstack-tripleo-common: RHOSP Director Disables TLS Verification for Registry Mirrors
vendor_redhat·2024-08-20·CVSS 8.1
CVE-2024-8007 [HIGH] CWE-295 openstack-tripleo-common: RHOSP Director Disables TLS Verification for Registry Mirrors
openstack-tripleo-common: RHOSP Director Disables TLS Verification for Registry Mirrors
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
Mitigation: Mitigation for this issue is either not available or the cu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-21
Published