CVE-2024-28716
HIGHOpenStack Storlets yoga-eom - Remote Code Execution via gateway.py
Title source: llmDescription
An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.
References (3)
Core 3
Core References
Issue Tracking
https://bugs.launchpad.net/solum/+bug/2047505
Various Sources
https://drive.google.com/file/d/11x-6CjWCyap8_W1JpVzun56HQkPNLtWT/view?usp=drive_link
Various Sources
https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f
Scores
CVSS v3
7.5
EPSS
0.0137
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Published
Apr 30, 2024
Tracked Since
Feb 18, 2026