OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.0, < 26.1.7CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 27.0.0, < 29.0.6CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 30.0.0, < 32.0.2CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 33.0.0, < 35.0.2CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.