Openstack

Ironic

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 14.08.2026 22:53:18
  • Zuletzt bearbeitet 17.08.2026 16:17:48

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

  • EPSS 0.16%
  • Veröffentlicht 05.08.2026 06:19:33
  • Zuletzt bearbeitet 05.08.2026 18:17:15

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

  • EPSS 0.3%
  • Veröffentlicht 10.07.2026 03:10:54
  • Zuletzt bearbeitet 10.07.2026 18:51:16

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

  • EPSS 0.33%
  • Veröffentlicht 10.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 18:50:20

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.

  • EPSS 0.29%
  • Veröffentlicht 14.06.2026 03:49:37
  • Zuletzt bearbeitet 23.07.2026 10:10:00

In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST...

  • EPSS 0.43%
  • Veröffentlicht 04.06.2026 23:59:20
  • Zuletzt bearbeitet 23.07.2026 07:10:00

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

  • EPSS 0.6%
  • Veröffentlicht 04.06.2026 00:00:00
  • Zuletzt bearbeitet 22.07.2026 20:10:00

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

  • EPSS 0.28%
  • Veröffentlicht 04.06.2026 00:00:00
  • Zuletzt bearbeitet 22.07.2026 20:10:00

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

  • EPSS 0.26%
  • Veröffentlicht 03.06.2026 00:00:00
  • Zuletzt bearbeitet 22.07.2026 20:10:00

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

  • EPSS 0.47%
  • Veröffentlicht 14.05.2026 00:00:00
  • Zuletzt bearbeitet 20.05.2026 17:16:23

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.