Openstack

Ironic

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 14.05.2026 00:00:00
  • Zuletzt bearbeitet 14.05.2026 18:30:57

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

  • EPSS 0.01%
  • Veröffentlicht 08.05.2026 06:38:37
  • Zuletzt bearbeitet 12.05.2026 00:17:03

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

  • EPSS 0.01%
  • Veröffentlicht 05.05.2026 00:00:00
  • Zuletzt bearbeitet 07.05.2026 15:53:49

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to al...

  • EPSS 0.08%
  • Veröffentlicht 28.04.2026 04:53:10
  • Zuletzt bearbeitet 30.04.2026 04:16:14

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

  • EPSS 0.06%
  • Veröffentlicht 08.05.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-c...

  • EPSS 0.29%
  • Veröffentlicht 04.10.2024 18:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for s...

  • EPSS 0.27%
  • Veröffentlicht 06.09.2024 01:15:11
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unau...

  • EPSS 0.19%
  • Veröffentlicht 07.06.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.