CVE-2024-28718: Critical severity pip/magnum vulnerability
Published Apr 12, 2024
·Updated
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the certmanager.py. component.
Affected Software
5 affected componentsFixes available
pip/magnum>=15.0.0.0rc1<15.0.2
15.0.2
pip/magnum>=16.0.0.0rc1<16.0.2
16.0.2
pip/magnum>=17.0.0.0rc1<17.0.2
17.0.2
pip/magnum<14.1.2
14.1.2
Openstack Magnum
Remediation
Patch Available
Patch Available
Event History
Apr 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
Description
Data Sourced
via NVD·01:15 PM
RemedySeverityWeaknessAffected Software
Advisory Published
via GitHub·03:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-28718?
CVE-2024-28718 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-28718?
To fix CVE-2024-28718, upgrade the magnum package to version 15.0.2, 16.0.2, 17.0.2, or any version higher than 14.1.2.
3
What component is affected in CVE-2024-28718?
The cert_manager.py component is the affected part in CVE-2024-28718.
4
What type of vulnerability is CVE-2024-28718?
CVE-2024-28718 is a remote code execution vulnerability.
5
Which software versions are impacted by CVE-2024-28718?
CVE-2024-28718 impacts OpenStack magnum versions from 15.0.0.0rc1 up to 15.0.2, 16.0.0.0rc1 up to 16.0.2, and 17.0.0.0rc1 up to 17.0.2, along with any versions prior to 14.1.2.