| Vulnerability Name: | CVE-2018-14620 (CCN-150094) | ||||||||||||
| Assigned: | 2018-09-10 | ||||||||||||
| Published: | 2018-09-10 | ||||||||||||
| Updated: | 2021-08-04 | ||||||||||||
| Summary: | The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable. | ||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
4.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-14620 Source: REDHAT Type: Vendor Advisory RHSA-2018:2721 Source: REDHAT Type: Vendor Advisory RHSA-2018:2729 Source: CCN Type: Red Hat Bugzilla Bug 1626953 (CVE-2018-14620) CVE-2018-14620 openstack-rabbitmq-container: Insecure download of rabbitmq_clusterer during docker build Source: CONFIRM Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14620 Source: CCN Type: OpenStack Web site Message queue Source: XF Type: UNKNOWN openstack-cve201814620-code-exec(150094) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||