6.3
CVE-2026-90461
- EPSS 0.21%
- Veröffentlicht 11.09.2026 21:32:33
- Zuletzt bearbeitet 22.09.2026 19:56:19
- Erkennungen
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenStack
≫
Produkt
Ironic
Default Statusunaffected
Version <=
29.0.6
Version
24.0.0
Status
affected
Version <=
32.0.1
Version
30.0.0
Status
affected
Version <=
35.0.1
Version
33.0.0
Status
affected
Version <=
38.0.0
Version
36.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.109 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 6.3 | 1.8 | 4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-923 Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
https://bugs.launchpad.net/ironic/+bug/2162816