CVE Vulnerabilities

CVE-2024-8007

Improper Certificate Validation

Published: Aug 21, 2024 | Modified: Nov 25, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Openstack_platformRedhat16.1 (including)16.1 (including)
Openstack_platformRedhat16.2 (including)16.2 (including)
Openstack_platformRedhat17.1 (including)17.1 (including)
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatopenstack-tripleo-common-0:15.4.1-17.1.20240911093743.e5b18f2.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 8RedHatpython-tripleoclient-0:16.5.1-17.1.20240913093745.f3599d0.el8ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatopenstack-tripleo-common-0:15.4.1-17.1.20240911100820.e5b18f2.el9ost*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatpython-tripleoclient-0:16.5.1-17.1.20240913100806.f3599d0.el9ost*

Potential Mitigations

References