CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-26943

CRITICAL
9.9
CVSS Severity Score
EPSS Score0.1290%
EPSS Percentile22.49th
Published2020年10月16日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

Affected Platforms (CPE)

📦
Openstack

Blazar Dashboard

< 1.3.1
📦
Openstack

Blazar Dashboard

= 2.0.0
📦
Openstack

Blazar Dashboard

= 3.0.0

References & Advisories

相關漏洞威脅