CVE-2024-8007
Last modified
CVE-2024-8007 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack Platform | 16.1 |
| Redhat | Openstack Platform | 16.2 |
| Redhat | Openstack Platform | 17.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-8007?
How severe is CVE-2024-8007?
How do I fix CVE-2024-8007?
Are you affected by CVE-2024-8007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
