Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxvx-hwwh-pp7c

Опубликовано: 10 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

EPSS

Процентиль: 41%
0.00516
Низкий

8.2 High

CVSS3

Дефекты

CWE-424

Связанные уязвимости

CVSS3: 8.2
ubuntu
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

CVSS3: 6.5
redhat
27 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

CVSS3: 8.2
nvd
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

CVSS3: 8.2
debian
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to ...

EPSS

Процентиль: 41%
0.00516
Низкий

8.2 High

CVSS3

Дефекты

CWE-424