A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2024:9990 | |
https://access.redhat.com/errata/RHSA-2024:9991 | |
https://access.redhat.com/security/cve/CVE-2024-8007 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2305975 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-08-21 14:15
Updated : 2024-11-25 05:15
NVD link : CVE-2024-8007
Mitre link : CVE-2024-8007
CVE.ORG link : CVE-2024-8007
JSON object : View
Products Affected
redhat
- openstack_platform
CWE
CWE-295
Improper Certificate Validation