CVE-2020-26943: Code Injection
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-26943.
What is the severity level of CVE-2020-26943?
The severity level of CVE-2020-26943 is critical with a score of 9.9.
What is affected by CVE-2020-26943?
OpenStack blazar-dashboard versions before 1.3.1, 2.0.0, and 3.0.0 are affected by CVE-2020-26943.
How can an attacker exploit CVE-2020-26943?
An attacker with access to the Blazar dashboard in Horizon can trigger code execution on the Horizon host.
Is there a fix available for CVE-2020-26943?
Yes, the fix for CVE-2020-26943 is available in OpenStack blazar-dashboard 1.3.1, 2.0.0, and 3.0.0.