Total vulnerabilities in the database
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Software | From | Fixed in |
---|---|---|
redhat / openstack | 7.0 | 7.0.x |
redhat / openstack | 8 | 8.x |
canonical / openstack_ironic | - | 4.2.4.x |
canonical / openstack_ironic | 5.1.1 | 5.1.1.x |
canonical / openstack_ironic | 5.1.0 | 5.1.0.x |