Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTkzOW0tNHhwdy12MzR2

Arbitrary Code Execution in blazar-dashboard

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

Permalink: https://github.com/advisories/GHSA-939m-4xpw-v34v
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTkzOW0tNHhwdy12MzR2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 4 years ago
Updated: 2 months ago


CVSS Score: 10.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Identifiers: GHSA-939m-4xpw-v34v, CVE-2020-26943
References: Blast Radius: 0.0

Affected Packages

pypi:blazar-dashboard
Dependent packages: 0
Dependent repositories: 1
Downloads: 1,101 last month
Affected Version Ranges: = 3.0.0, = 2.0.0, < 1.3.1
Fixed in: 3.0.1, 2.0.1, 1.3.1
All affected versions: 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.3.0, 2.0.0, 3.0.0
All unaffected versions: 1.3.1, 2.0.1, 3.0.1, 4.0.0, 5.0.0, 6.0.0, 7.0.0, 8.0.0, 9.0.0, 9.0.1, 10.0.0, 11.0.0, 12.0.0