VendorsOpenStackmagnumall versions
Vulnerabilities

OpenStack Magnum

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-7404
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.
Published 2019-06-21 · Modified
9.8EPSS 0.019
CVE-2024-28718
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
Published 2024-04-12 · Analyzed
9.8EPSS 0.011