Skip to content

Arbitrary Code Execution in blazar-dashboard

Moderate severity GitHub Reviewed Published Oct 27, 2020 to the GitHub Advisory Database • Updated Sep 6, 2024

Package

pip blazar-dashboard (pip)

Affected versions

< 1.3.1
= 2.0.0
= 3.0.0

Patched versions

1.3.1
2.0.1
3.0.1

Description

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

References

Reviewed Oct 26, 2020
Published to the GitHub Advisory Database Oct 27, 2020
Last updated Sep 6, 2024

Severity

Moderate

EPSS score

0.233%
(62nd percentile)

Weaknesses

CVE ID

CVE-2020-26943

GHSA ID

GHSA-939m-4xpw-v34v

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.