CVE Database · CVE-2016-7404
CVSS v3.1
N/A
EPSS
1.87%
Published
Jun 21, 2019
Modified
Nov 20, 2024
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be used to perform any API operation the user is authorized to perform.
Weaknesses (CWE)
Affected Products (1)
References (8)