Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44916

Опубликовано: 08 мая 2026
Источник: debian

Описание

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ironicfixed1:35.0.1-2package
ironicfixed1:29.0.5-0+deb13u1trixiepackage
ironicfixed1:21.1.0-3+deb12u1bookwormpackage
ironicno-dsabullseyepackage

Примечания

  • https://bugs.launchpad.net/ironic/+bug/2148307

  • https://review.opendev.org/c/openstack/ironic/+/987514

Связанные уязвимости

CVSS3: 3
ubuntu
3 месяца назад

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

CVSS3: 3
nvd
3 месяца назад

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

CVSS3: 3
github
3 месяца назад

In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing.