{"id":"CVE-2024-28718","aliases":["GHSA-jx7x-9r98-h5xr","PYSEC-2026-1602"],"title":"OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack","summary":"OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","vendor":"magnum","product":"magnum","ecosystem":"pip","affected":["magnum < 14.1.2","magnum >= 17.0.0.0rc1, < 17.0.2","magnum >= 16.0.0.0rc1, < 16.0.2","magnum >= 15.0.0.0rc1, < 15.0.2"],"patched":["magnum 14.1.2","magnum 17.0.2","magnum 16.0.2","magnum 15.0.2"],"published":"2024-04-12","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jx7x-9r98-h5xr","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28718"},{"url":"https://github.com/openstack/magnum/commit/272fd686d8c8bf5954e9e7d3bc991ff27e46184d"},{"url":"https://github.com/openstack/magnum/commit/312aa6a86ac8e62f6ed4f1e9473fdabbbb7a4b1e"},{"url":"https://github.com/openstack/magnum/commit/883b40b5b0ecfc5f78758143c0d3c754458f12b7"},{"url":"https://github.com/openstack/magnum/commit/e79907c521149872c1b495355a3a7b3a0c7e3479"},{"url":"https://bugs.launchpad.net/magnum/+bug/2047690"},{"url":"https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f"},{"url":"https://github.com/openstack/magnum"},{"url":"https://review.opendev.org/c/openstack/magnum/+/907305"}],"tags":["osv","pip"],"epss":0.01063,"epssPercentile":0.63218,"ingestedAt":"2026-07-08T18:25:50.902Z","slug":"CVE-2024-28718","body":"## Overview\n\nAn issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.\n\n## Affected packages\n\n- `magnum < 14.1.2`\n- `magnum >= 17.0.0.0rc1, < 17.0.2`\n- `magnum >= 16.0.0.0rc1, < 16.0.2`\n- `magnum >= 15.0.0.0rc1, < 15.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `magnum 14.1.2`\n- `magnum 17.0.2`\n- `magnum 16.0.2`\n- `magnum 15.0.2`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}