instack-undercloud
instack-undercloud
Activity
- Latest release
- 7y ago
- Total releases
- 78
- Cadence
- ~4 days
- Last 12 months
- 0
Details
- First release
- Jun 06, 2016
| Version | Released | |
|---|---|---|
8.4.9
patch
|
8.4.9
patch
Dependencies (15)
+ 7 more |
|
9.5.1
patch
|
9.5.1
patch
Dependencies (16)
+ 8 more |
|
8.4.8
patch
|
8.4.8
patch
Dependencies (15)
+ 7 more |
|
7.4.15
patch
|
7.4.15
patch
Dependencies (14)
+ 6 more |
|
8.4.7
patch
|
8.4.7
patch
Dependencies (15)
+ 7 more |
|
9.5.0
minor
|
9.5.0
minor
Dependencies (16)
+ 8 more |
|
8.4.6
patch
|
8.4.6
patch
Dependencies (15)
+ 7 more |
|
9.4.0
minor
|
9.4.0
minor
Dependencies (15)
+ 7 more |
|
8.4.5
patch
|
8.4.5
patch
Dependencies (15)
+ 7 more |
|
9.3.0
minor
|
9.3.0
minor
Dependencies (15)
+ 7 more |
|
8.4.4
patch
|
8.4.4
patch
Dependencies (15)
+ 7 more |
|
7.4.14
patch
|
7.4.14
patch
Dependencies (14)
+ 6 more |
|
9.2.0
minor
|
9.2.0
minor
Dependencies (15)
+ 7 more |
|
7.4.13
patch
|
7.4.13
patch
Dependencies (14)
+ 6 more |
|
6.1.8
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.8
patch
Dependencies (10)
+ 2 more |
|
8.4.3
patch
|
8.4.3
patch
Dependencies (15)
+ 7 more |
|
5.3.10
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.10
patch
Dependencies (11)
+ 3 more |
|
9.1.0
minor
|
9.1.0
minor
Dependencies (15)
+ 7 more |
|
8.4.2
patch
|
8.4.2
patch
Dependencies (15)
+ 7 more |
|
7.4.12
patch
|
7.4.12
patch
Dependencies (14)
+ 6 more |
|
5.3.9
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.9
patch
Dependencies (11)
+ 3 more |
|
6.1.7
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.7
patch
Dependencies (10)
+ 2 more |
|
8.4.1
patch
|
8.4.1
patch
Dependencies (15)
+ 7 more |
|
9.0.0
major
|
9.0.0
major
Dependencies (15)
+ 7 more |
|
8.4.0
minor
|
8.4.0
minor
Dependencies (15)
+ 7 more |
|
5.3.8
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.8
patch
Dependencies (11)
+ 3 more |
|
7.4.11
patch
|
7.4.11
patch
Dependencies (14)
+ 6 more |
|
6.1.6
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.6
patch
Dependencies (10)
+ 2 more |
|
7.4.10
patch
|
7.4.10
patch
Dependencies (14)
+ 6 more |
|
8.3.0
minor
|
8.3.0
minor
Dependencies (15)
+ 7 more |
|
7.4.9
patch
|
7.4.9
patch
Dependencies (14)
+ 6 more |
|
6.1.5
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.5
patch
Dependencies (10)
+ 2 more |
|
8.2.0
minor
|
8.2.0
minor
Dependencies (15)
+ 7 more |
|
6.1.4
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.4
patch
Dependencies (10)
+ 2 more |
|
7.4.8
patch
|
7.4.8
patch
Dependencies (14)
+ 6 more |
|
5.3.7
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.7
patch
Dependencies (11)
+ 3 more |
|
7.4.7
patch
|
7.4.7
patch
Dependencies (14)
+ 6 more |
|
5.3.6
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.6
patch
Dependencies (11)
+ 3 more |
|
7.4.6
patch
|
7.4.6
patch
Dependencies (14)
+ 6 more |
|
8.1.0
minor
|
8.1.0
minor
Dependencies (15)
+ 7 more |
|
7.4.5
patch
|
7.4.5
patch
Dependencies (14)
+ 6 more |
|
5.3.5
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.5
patch
Dependencies (11)
+ 3 more |
|
6.1.3
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.3
patch
Dependencies (10)
+ 2 more |
|
7.4.4
patch
|
7.4.4
patch
Dependencies (14)
+ 6 more |
|
5.3.4
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.4
patch
Dependencies (11)
+ 3 more |
|
7.4.3
patch
|
7.4.3
patch
Dependencies (14)
+ 6 more |
|
6.1.2
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
6.1.2
patch
Dependencies (10)
+ 2 more |
|
5.3.3
patch
1 CVE
CVE-2017-7549
PYSEC-2026-645
GHSA-53wm-97p6-582f
PYSEC-2017-152
Jul 02, 2026
instack-undercloud vulnerable to symlink attack on tmp files
6.4
/ 10
Medium
Local
High
Low
None
Changed
High
Low
None
A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. Affected versions
4.0.1.dev90
4.1.0
4.2.0
4.2.1
5.0.0
5.0.0.0b1
5.0.0.0b2
5.0.0.0b3
5.0.0.0rc1
5.0.0.0rc2
5.0.0.0rc3
5.1.0
+ 29 more Show less
5.2.0
5.3.0
5.3.1
5.3.10
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
6.0.0
6.0.0.0b2
6.0.0.0rc1
6.0.0.0rc2
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
7.0.0
7.0.0.0b1
7.1.0
7.2.0
References Updated Jul 06, 2026 · Source: OSV.dev |
5.3.3
patch
Dependencies (11)
+ 3 more |
|
8.0.0
major
|
8.0.0
major
Dependencies (15)
+ 7 more |
|
7.4.2
patch
|
7.4.2
patch
Dependencies (13)
+ 5 more |