OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.0, < 26.1.7CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 27.0.0, < 29.0.6CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 30.0.0, < 32.0.2CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | ||
>= 33.0.0, < 35.0.2CPE match | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.