---
id: CVE-2024-28718
aliases:
  - GHSA-jx7x-9r98-h5xr
  - PYSEC-2026-1602
title: OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
summary: OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
vendor: magnum
product: magnum
ecosystem: pip
affected:
  - magnum < 14.1.2
  - 'magnum >= 17.0.0.0rc1, < 17.0.2'
  - 'magnum >= 16.0.0.0rc1, < 16.0.2'
  - 'magnum >= 15.0.0.0rc1, < 15.0.2'
patched:
  - magnum 14.1.2
  - magnum 17.0.2
  - magnum 16.0.2
  - magnum 15.0.2
published: '2024-04-12'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jx7x-9r98-h5xr'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-28718'
  - url: >-
      https://github.com/openstack/magnum/commit/272fd686d8c8bf5954e9e7d3bc991ff27e46184d
  - url: >-
      https://github.com/openstack/magnum/commit/312aa6a86ac8e62f6ed4f1e9473fdabbbb7a4b1e
  - url: >-
      https://github.com/openstack/magnum/commit/883b40b5b0ecfc5f78758143c0d3c754458f12b7
  - url: >-
      https://github.com/openstack/magnum/commit/e79907c521149872c1b495355a3a7b3a0c7e3479
  - url: 'https://bugs.launchpad.net/magnum/+bug/2047690'
  - url: 'https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f'
  - url: 'https://github.com/openstack/magnum'
  - url: 'https://review.opendev.org/c/openstack/magnum/+/907305'
tags:
  - osv
  - pip
epss: 0.01063
epssPercentile: 0.6319
ingestedAt: '2026-07-08T18:25:50.902Z'
---

## Overview

An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

## Affected packages

- `magnum < 14.1.2`
- `magnum >= 17.0.0.0rc1, < 17.0.2`
- `magnum >= 16.0.0.0rc1, < 16.0.2`
- `magnum >= 15.0.0.0rc1, < 15.0.2`

## Remediation

Upgrade to a patched release:

- `magnum 14.1.2`
- `magnum 17.0.2`
- `magnum 16.0.2`
- `magnum 15.0.2`
