CVE-2016-7404: Infoleak
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-7404?
CVE-2016-7404 is a vulnerability in OpenStack Magnum that allows unauthorized users to perform any API operation.
How does CVE-2016-7404 work?
CVE-2016-7404 occurs when OpenStack Magnum passes OpenStack credentials into the Heat templates, providing full API access to unauthorized users.
What is the severity of CVE-2016-7404?
CVE-2016-7404 has a severity score of 9.8, indicating a critical vulnerability.
How can I fix CVE-2016-7404?
To fix CVE-2016-7404, it is recommended to upgrade OpenStack Magnum to version 5.0.0 or higher.
Where can I find more information about CVE-2016-7404?
You can find more information about CVE-2016-7404 at the following references: [Reference 1](https://nvd.nist.gov/vuln/detail/CVE-2016-7404), [Reference 2](https://bugs.launchpad.net/magnum/+bug/1620536), [Reference 3](https://bugzilla.suse.com/show_bug.cgi?id=998182).