Bugzilla – Bug 1222861
VUL-0: CVE-2024-28718: openstack-magnum: TOCTOU issue when creating client certificate files in cert-manager.py
Last modified: 2024-05-13 06:04:03 UTC
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28718 https://www.cve.org/CVERecord?id=CVE-2024-28718 https://bugs.launchpad.net/magnum/+bug/2047690 https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f https://review.opendev.org/c/openstack/magnum/+/907305
The fix for this issue can be found at: - https://review.opendev.org/c/openstack/magnum/+/907305
SOC is EOL, please refer to https://jira.suse.com/browse/MSC-777. Back to Security team.