CVE-2016-7404
Summary
| CVE | CVE-2016-7404 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-21 14:15:00 UTC |
| Updated | 2019-06-26 19:22:00 UTC |
| Description | OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix CVE-2016-7404 · 0bb0d6486d - magnum - OpenDev: Free Software Needs Free Tools | CONFIRM | opendev.org | Patch, Third Party Advisory |
| Bug 998182 – VUL-0: CVE-2016-7404: openstack-magnum: Magnum created instances have full API access to creating user's OpenStack account | MISC | bugzilla.suse.com | Issue Tracking, Patch, Third Party Advisory |
| Error: Page not found | MISC | bugs.launchpad.net | Broken Link, Issue Tracking, Third Party Advisory |
| OpenStack Magnum CVE-2016-7404 Multiple Security Bypass Vulnerabilities | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.