Improper Validation of Integrity Check Value Affecting openstack-ironic-api package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-OPENSTACKIRONICAPI-8167866
  • published8 Oct 2024
  • disclosed3 Oct 2024

Introduced: 3 Oct 2024

CVE-2024-47211  (opens in a new tab)
CWE-354  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:8 openstack-ironic-api.

NVD Description

Note: Versions mentioned in the description apply only to the upstream openstack-ironic-api package and not the openstack-ironic-api package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

CVSS Base Scores

version 3.1