ironic@26.1.5

OpenStack Bare Metal Provisioning

  • latest version

    38.0.0

  • first published

    7 years ago

  • latest version published

    13 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ironic package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Missing Authorization

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Missing Authorization in the send_raw process. An attacker can gain unauthorized control over hardware or cause a system outage by sending arbitrary IPMI commands to the BMC. This is only exploitable if administrator privileges have been explicitly delegated to project-level roles with owner or lessee capabilities, and the automatic_lessee feature is enabled and functioning.

    How to fix Missing Authorization?

    Upgrade ironic to version 38.0.0 or higher.

    [0,38.0.0)
    • H
    Insufficient Granularity of Access Control

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the process of reparenting Volume Connectors and Volume Targets to nodes in a different project, crossing project authorization boundaries. An attacker can gain unauthorized access to iSCSI secrets and manipulate node operations by leveraging knowledge of the UUID of a target node in another project and possessing the 'manager' role. This is only exploitable if the attacker has been explicitly granted the 'manager' role and knows the UUID of the target node in the other project.

    How to fix Insufficient Granularity of Access Control?

    Upgrade ironic to version 38.0.0 or higher.

    [0,38.0.0)
    • H
    Arbitrary Code Injection

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the boot script processing. An attacker can execute arbitrary commands on affected systems by injecting malicious scripts during the boot process.

    How to fix Arbitrary Code Injection?

    A fix was pushed into the master branch but not yet published.

    [17.0.0,)
    • M
    Incorrect Behavior Order

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Incorrect Behavior Order. OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices. In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

    How to fix Incorrect Behavior Order?

    Upgrade ironic to version 29.0.6, 37.0.0 or higher.

    [,29.0.6)[30.0.0,37.0.0)
    • M
    Insertion of Sensitive Information Into Sent Data

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the PATCH process on volume properties. An attacker can obtain sensitive information by sending a PATCH request to update volume properties they are authorized for, which may result in the exposure of unredacted confidential data such as iSCSI credentials.

    How to fix Insertion of Sensitive Information Into Sent Data?

    A fix was pushed into the master branch but not yet published.

    [17.0.0,)
    • H
    Directory Traversal

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Directory Traversal via the deployment process when handling a crafted ISO image. An attacker can read or modify files on the target system by supplying attacker-controlled ISO content during node deployment.

    How to fix Directory Traversal?

    Upgrade ironic to version 29.0.6, 36.0.0 or higher.

    [17.0.0,29.0.6)[30.0.0,36.0.0)
    • H
    Incorrect Resource Transfer Between Spheres

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Incorrect Resource Transfer Between Spheres in the import process when a user invokes molds and requests authorization to be sent to a remote endpoint. The credential forwarded is a time-limited token or basic credentials configured for molds storage. An attacker can gain unauthorized access to resources by leveraging the forwarding of these credentials to a remote endpoint.

    How to fix Incorrect Resource Transfer Between Spheres?

    Upgrade ironic to version 26.1.6, 29.0.5, 32.0.1, 35.0.1 or higher.

    [,26.1.6)[27.0.0,29.0.5)[30.0.0,32.0.1)[33.0.0,35.0.1)
    • H
    Unsafe Dependency Resolution

    ironic is an OpenStack Bare Metal Provisioning

    Affected versions of this package are vulnerable to Unsafe Dependency Resolution in the ipmitool process when a non-default configuration enables a console interface. An attacker can execute unauthorized commands by leveraging access to the untrusted control sphere. This is only exploitable if the console interface is enabled in a non-default configuration.

    How to fix Unsafe Dependency Resolution?

    Upgrade ironic to version 26.1.6, 29.0.5, 32.0.1, 35.0.1 or higher.

    [,26.1.6)[27.0.0,29.0.5)[30.0.0,32.0.1)[33.0.0,35.0.1)