{"id":"UBUNTU-CVE-2024-28718","details":"An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.","modified":"2026-05-20T16:17:12.224626067Z","published":"2024-04-12T13:15:00Z","upstream":["CVE-2024-28718"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-28718"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-28718"},{"type":"REPORT","url":"https://bugs.launchpad.net/magnum/+bug/2047690"},{"type":"REPORT","url":"https://review.opendev.org/c/openstack/magnum/+/907305"},{"type":"REPORT","url":"https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f"}],"affected":[{"package":{"name":"magnum","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0~b1-5","2.0.0-4ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"magnum-api","binary_version":"2.0.0-4ubuntu1"},{"binary_version":"2.0.0-4ubuntu1","binary_name":"magnum-common"},{"binary_name":"magnum-conductor","binary_version":"2.0.0-4ubuntu1"},{"binary_name":"python-magnum","binary_version":"2.0.0-4ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.1-0ubuntu1","6.0.1-0ubuntu1","6.1.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.1.0-0ubuntu1","binary_name":"magnum-api"},{"binary_name":"magnum-common","binary_version":"6.1.0-0ubuntu1"},{"binary_name":"magnum-conductor","binary_version":"6.1.0-0ubuntu1"},{"binary_version":"6.1.0-0ubuntu1","binary_name":"python-magnum"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.0-0ubuntu1","10.0.0~b2~git2020020609.16ea8b63-0ubuntu1","10.0.0~b3~git2020032617.ce70da25-0ubuntu1","10.0.0~b3~git2020041013.01629398-0ubuntu1","10.0.0-0ubuntu0.20.04.1","10.0.0-0ubuntu0.20.04.2","10.1.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"magnum-api","binary_version":"10.1.0-0ubuntu1"},{"binary_name":"magnum-common","binary_version":"10.1.0-0ubuntu1"},{"binary_name":"magnum-conductor","binary_version":"10.1.0-0ubuntu1"},{"binary_name":"python3-magnum","binary_version":"10.1.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["13.0.0-0ubuntu1","13.0.0+git2021120910.fa298eea-0ubuntu1","13.0.0+git2022030313.4c4bba13-0ubuntu1","13.0.0+git2022030313.4c4bba13-0ubuntu2","14.0.0-0ubuntu1","14.1.0-0ubuntu1","14.1.1-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"magnum-api","binary_version":"14.1.1-0ubuntu1"},{"binary_version":"14.1.1-0ubuntu1","binary_name":"magnum-common"},{"binary_name":"magnum-conductor","binary_version":"14.1.1-0ubuntu1"},{"binary_name":"python3-magnum","binary_version":"14.1.1-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.0.0-0ubuntu1","17.0.1+git2023121308.537e69ae-0ubuntu1","17.0.1+git2024011916.f6baa6d1-0ubuntu1","18.0.0~rc1-0ubuntu1","18.0.0-0ubuntu1","18.0.1-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"18.0.1-0ubuntu1","binary_name":"magnum-api"},{"binary_version":"18.0.1-0ubuntu1","binary_name":"magnum-common"},{"binary_name":"magnum-conductor","binary_version":"18.0.1-0ubuntu1"},{"binary_name":"python3-magnum","binary_version":"18.0.1-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20.0.0-0ubuntu1","20.0.0+git2025070714.cbeb6a89-0ubuntu1","21.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"21.0.0-0ubuntu1","binary_name":"magnum-api"},{"binary_name":"magnum-common","binary_version":"21.0.0-0ubuntu1"},{"binary_name":"magnum-conductor","binary_version":"21.0.0-0ubuntu1"},{"binary_name":"python3-magnum","binary_version":"21.0.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}},{"package":{"name":"magnum","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/magnum?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["21.0.0-0ubuntu1","21.0.0+git20260120.23.f2342172-0ubuntu1","22.0.0~rc1-0ubuntu2","22.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"magnum-api","binary_version":"22.0.0-0ubuntu1"},{"binary_version":"22.0.0-0ubuntu1","binary_name":"magnum-common"},{"binary_version":"22.0.0-0ubuntu1","binary_name":"magnum-conductor"},{"binary_name":"python3-magnum","binary_version":"22.0.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-28718.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}