Friday, June 21, 2019

New vulnerability on the NVD: CVE-2016-7404

OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.

Published at: June 21, 2019 at 05:15PM
View on website

No comments:

Post a Comment