MEDIUM6.3
PYSEC-2026-1602
OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
Quick fix
PYSEC-2026-1602 — magnum: upgrade to the fixed version with the command below.
pip install --upgrade 'magnum>=14.1.2'Details
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-28718[ADVISORY]
- https://github.com/openstack/magnum/commit/272fd686d8c8bf5954e9e7d3bc991ff27e46184d[WEB]
- https://github.com/openstack/magnum/commit/312aa6a86ac8e62f6ed4f1e9473fdabbbb7a4b1e[WEB]
- https://github.com/openstack/magnum/commit/883b40b5b0ecfc5f78758143c0d3c754458f12b7[WEB]
- https://github.com/openstack/magnum/commit/e79907c521149872c1b495355a3a7b3a0c7e3479[WEB]
- https://bugs.launchpad.net/magnum/+bug/2047690[WEB]
- https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f[WEB]
- https://github.com/openstack/magnum[PACKAGE]
- https://review.opendev.org/c/openstack/magnum/+/907305[WEB]
- https://pypi.org/project/magnum[PACKAGE]
- https://github.com/advisories/GHSA-jx7x-9r98-h5xr[ADVISORY]