← Back

CVE-2024-8007

nvd nist
Published: Aug 21, 2024Modified: Nov 25, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.

Affected (3)

1 product
Openstack Platform
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 16.1
Version 16.2
Version 17.1

References (4)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.