CVE-2020-26943 is a critical vulnerability affecting OpenStack blazar-dashboard versions prior to 1.3.1, 2.0.0, and 3.0.0. It allows an authenticated user with Blazar dashboard access to achieve remote code execution on the Horizon host due to the improper use of Python's eval function. This vulnerability carries a CVSS score of 9.9 (CRITICAL) with a low attack complexity, enabling unauthorized access and potential compromise of the Horizon service. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.1CPE matchmatch criteria | cpe:2.3:a:openstack:blazar-dashboard:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:openstack:blazar-dashboard:2.0.0:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:openstack:blazar-dashboard:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.