Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8xwf-cr4r-856r | OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 27 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack vitrage |
|
| CPEs | cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack vitrage |
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py. | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-05T04:34:01.128Z
Reserved: 2026-02-27T04:52:33.518Z
Link: CVE-2026-28370
Updated: 2026-03-05T04:34:01.128Z
Status : Modified
Published: 2026-02-27T05:18:20.757
Modified: 2026-03-05T05:16:37.117
Link: CVE-2026-28370
No data.
OpenCVE Enrichment
Updated: 2026-03-02T12:07:25Z
Github GHSA