CVE-2024-8007: Red Hat Openstack Platform
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
Affected products
- Red Hat Openstack Platform: version 16.1 only; version 16.2 only; version 17.1 only
Published 2024-08-21. Last modified 2026-06-17.