5.5
CVE-2026-54422
- EPSS 0.12%
- Veröffentlicht 24.07.2026 03:42:26
- Zuletzt bearbeitet 24.07.2026 13:18:27
- CVE-Watchlists
- Unerledigt
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenStack
≫
Produkt
Ironic Python Agent
Default Statusunaffected
Version
10.2.0
Version <
10.2.3
Status
affected
Version
11.0.0
Version <
11.2.1
Status
affected
Version
11.3.0
Version <
11.5.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 5.5 | 1 | 4 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://bugs.launchpad.net/ironic-python-agent/+bug/2155826
https://www.openwall.com/lists/oss-security/2026/07/23/4
https://security.openstack.org/ossa/OSSA-2026-028.html
http://www.openwall.com/lists/oss-security/2026/07/23/4