CVE-2024-8007
Openstack-tripleo-common: rhosp director disables tls verification for registry mirrors
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
21 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
openstack-tripleo-commonRed Hat · Red Hat OpenStack Platform 16.1Red Hat · Red Hat OpenStack Platform 16.2Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 8Red Hat · Red Hat OpenStack Platform 17.1 for RHEL 9Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →