5.5

CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenStack
≫
Produkt Ironic Python Agent
Default Statusunaffected
Version 10.2.0
Version < 10.2.3
Status affected
Version 11.0.0
Version < 11.2.1
Status affected
Version 11.3.0
Version < 11.5.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MITRE 5.5 1 4
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://bugs.launchpad.net/ironic-python-agent/+bug/2155826
https://www.openwall.com/lists/oss-security/2026/07/23/4
https://security.openstack.org/ossa/OSSA-2026-028.html
http://www.openwall.com/lists/oss-security/2026/07/23/4