OSV 1.4.0 · unreviewed · 修改于 2026-09-01 20:31
发布时间
2026-09-01 20:31
GitHub 审查时间
—
NVD 发布时间
2026-09-01 19:16
源文件
advisories/unreviewed/2026/09/GHSA-m4j2-w8wf-vp83/GHSA-m4j2-w8wf-vp83.json
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the one.vm.exec function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
该公告没有提供结构化的受影响软件包信息。