Openstack
Openstack Ironic: vulnerabilidades y CVE
Openstack Ironic tiene 20 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses15
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71568 | Media (5.3) | 0.23% | — | 17 sept 2026 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly… |
| CVE-2026-90461 | Media (6.3) | 0.33% | — | 11 sept 2026 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. |
| CVE-2026-74250 | Media (6.3) | 0.30% | — | 14 ago 2026 | In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. |
| CVE-2026-71201 | Media (5) | 0.28% | — | 5 ago 2026 | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project. |
| CVE-2026-54423 | Alta (8.2) | 0.48% | — | 10 jul 2026 | In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's… |
| CVE-2026-44918 | Media (5.5) | 0.41% | — | 10 jul 2026 | OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. |
| CVE-2026-54421 | Media (6.8) | 0.47% | — | 14 jun 2026 | In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH… |
| CVE-2026-50589 | Alta (7.5) | 0.74% | — | 5 jun 2026 | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. |
| CVE-2026-48681 | Alta (8.1) | 0.85% | — | 4 jun 2026 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. |
| CVE-2026-44917 | Media (4.9) | 0.47% | — | 4 jun 2026 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. |
| CVE-2026-46447 | Alta (7.7) | 0.43% | — | 3 jun 2026 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. |
| CVE-2026-44919 | Media (6.5) | 0.56% | — | 14 may 2026 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. |
| CVE-2026-44916 | Baja (3) | 0.35% | — | 8 may 2026 | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing. |
| CVE-2026-42997 | Alta (7.7) | 0.54% | — | 5 may 2026 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone… |
| CVE-2026-42510 | Alta (7.2) | 0.74% | — | 28 abr 2026 | OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. |
| CVE-2025-44021 | Baja (2.8) | 0.18% | — | 8 may 2025 | OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any… |
| CVE-2024-47211 | Media (5.3) | 0.66% | — | 4 oct 2024 | In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to… |
| CVE-2024-44082 | Media (4.3) | 0.55% | — | 6 sept 2024 | In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in… |
| CVE-2024-31463 | Media (4.7) | 0.21% | — | 17 abr 2024 | Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, 1) HTTP basic credentials are… |
| CVE-2015-7514 | Media (6.5) | 1.6% | — | 7 jun 2017 | OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information. |