VYPR
Moderate severityNVD Advisory· Published Oct 16, 2020· Updated Aug 4, 2024

CVE-2020-26943

CVE-2020-26943

Description

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
blazar-dashboardPyPI
< 1.3.11.3.1
blazar-dashboardPyPI
>= 2.0.0, < 2.0.12.0.1
blazar-dashboardPyPI
>= 3.0.0, < 3.0.13.0.1

Affected products

2

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.