CVE-2026-44919
- EPSS 0.01%
- Veröffentlicht 14.05.2026 00:00:00
- Zuletzt bearbeitet 14.05.2026 18:30:57
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
- EPSS 0.01%
- Veröffentlicht 08.05.2026 06:38:37
- Zuletzt bearbeitet 12.05.2026 00:17:03
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
CVE-2026-42997
- EPSS 0.01%
- Veröffentlicht 05.05.2026 00:00:00
- Zuletzt bearbeitet 07.05.2026 15:53:49
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to al...
CVE-2026-42510
- EPSS 0.08%
- Veröffentlicht 28.04.2026 04:53:10
- Zuletzt bearbeitet 30.04.2026 04:16:14
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVE-2025-44021
- EPSS 0.06%
- Veröffentlicht 08.05.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-c...
CVE-2024-47211
- EPSS 0.29%
- Veröffentlicht 04.10.2024 18:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for s...
CVE-2024-44082
- EPSS 0.27%
- Veröffentlicht 06.09.2024 01:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unau...
CVE-2015-7514
- EPSS 0.19%
- Veröffentlicht 07.06.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.