38.0.0
7 years ago
13 days ago
Known vulnerabilities in the ironic package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? Upgrade | [0,38.0.0) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the process of reparenting Volume Connectors and Volume Targets to nodes in a different project, crossing project authorization boundaries. An attacker can gain unauthorized access to iSCSI secrets and manipulate node operations by leveraging knowledge of the UUID of a target node in another project and possessing the 'manager' role. This is only exploitable if the attacker has been explicitly granted the 'manager' role and knows the UUID of the target node in the other project. How to fix Insufficient Granularity of Access Control? Upgrade | [0,38.0.0) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Arbitrary Code Injection via the boot script processing. An attacker can execute arbitrary commands on affected systems by injecting malicious scripts during the boot process. How to fix Arbitrary Code Injection? A fix was pushed into the | [17.0.0,) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Incorrect Behavior Order. OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices. In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. How to fix Incorrect Behavior Order? Upgrade | [,29.0.6)[30.0.0,37.0.0) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the How to fix Insertion of Sensitive Information Into Sent Data? A fix was pushed into the | [17.0.0,) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Directory Traversal via the deployment process when handling a crafted ISO image. An attacker can read or modify files on the target system by supplying attacker-controlled ISO content during node deployment. How to fix Directory Traversal? Upgrade | [17.0.0,29.0.6)[30.0.0,36.0.0) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Incorrect Resource Transfer Between Spheres in the import process when a user invokes molds and requests authorization to be sent to a remote endpoint. The credential forwarded is a time-limited token or basic credentials configured for molds storage. An attacker can gain unauthorized access to resources by leveraging the forwarding of these credentials to a remote endpoint. How to fix Incorrect Resource Transfer Between Spheres? Upgrade | [,26.1.6)[27.0.0,29.0.5)[30.0.0,32.0.1)[33.0.0,35.0.1) |
ironic is an OpenStack Bare Metal Provisioning Affected versions of this package are vulnerable to Unsafe Dependency Resolution in the How to fix Unsafe Dependency Resolution? Upgrade | [,26.1.6)[27.0.0,29.0.5)[30.0.0,32.0.1)[33.0.0,35.0.1) |