OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugs.launchpad.net/magnum/+bug/1620536 | issue tracking third party advisory broken link |
https://bugzilla.suse.com/show_bug.cgi?id=998182 | issue tracking third party advisory patch |
https://www.securityfocus.com/bid/98467 | vdb entry third party advisory |
https://opendev.org/openstack/magnum/commit/0bb0d6486d6771ee21bbf897a091b1aa59e01b22 | third party advisory patch |