← Back to CVE List

CVE-2024-41961

Published: 2024-08-01T15:15Z
Last Modified: 2024-08-01T16:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an `eval` sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt