SAP-cloud-infrastructure/elektra

SAP-cloud-infrastructure/elektra

Releases13
Frequency7 months 2 weeks
Last Release
Stars80
An opinionated openstack Web UI for consumer self service and operations.

CVE History

CVEPublishedCVSS v3CVSS v2
9.6 CRITICAL

Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an `eval` sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02.