{"api_version":"1","generated_at":"2026-07-23T20:30:16+00:00","cve":"CVE-2016-7404","urls":{"html":"https://cve.report/CVE-2016-7404","api":"https://cve.report/api/cve/CVE-2016-7404.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-7404","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-7404"},"summary":{"title":"CVE-2016-7404","description":"OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-06-21 14:15:00","updated_at":"2019-06-26 19:22:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22","name":"https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"Fix CVE-2016-7404 · 0bb0d6486d -  magnum - OpenDev: Free Software Needs Free Tools","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=998182","name":"https://bugzilla.suse.com/show_bug.cgi?id=998182","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 998182 – VUL-0: CVE-2016-7404: openstack-magnum: Magnum created  instances have full API access to creating user's OpenStack account","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/magnum/+bug/1620536","name":"https://bugs.launchpad.net/magnum/+bug/1620536","refsource":"MISC","tags":["Broken Link","Issue Tracking","Third Party Advisory"],"title":"Error: Page not found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.securityfocus.com/bid/98467","name":"https://www.securityfocus.com/bid/98467","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"OpenStack Magnum CVE-2016-7404 Multiple Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-7404","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7404","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"7404","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"magnum","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7404","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"magnum","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-7404","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://bugs.launchpad.net/magnum/+bug/1620536","refsource":"MISC","name":"https://bugs.launchpad.net/magnum/+bug/1620536"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=998182","refsource":"MISC","name":"https://bugzilla.suse.com/show_bug.cgi?id=998182"},{"refsource":"MISC","name":"https://www.securityfocus.com/bid/98467","url":"https://www.securityfocus.com/bid/98467"},{"refsource":"CONFIRM","name":"https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22","url":"https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22"}]}},"nvd":{"publishedDate":"2019-06-21 14:15:00","lastModifiedDate":"2019-06-26 19:22:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:openstack:magnum:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"7404","Ordinal":"94021","Title":"CVE-2016-7404","CVE":"CVE-2016-7404","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"7404","Ordinal":"1","NoteData":"OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"7404","Ordinal":"2","NoteData":"2019-06-21","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"7404","Ordinal":"3","NoteData":"2019-06-21","Type":"Other","Title":"Modified"}]}}}