Описание
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Ссылки
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
- Mailing ListPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.3.0 (включая) до 26.1.6 (исключая)Версия от 27.0.0 (включая) до 29.0.5 (исключая)Версия от 30.0.0 (включая) до 32.0.1 (исключая)Версия от 33.0.0 (включая) до 35.0.1 (исключая)
Одно из
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00548
Низкий
6.6 Medium
CVSS3
7.2 High
CVSS3
Дефекты
CWE-829
Связанные уязвимости
CVSS3: 6.6
ubuntu
3 месяца назад
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVSS3: 6.6
redhat
3 месяца назад
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVSS3: 6.6
debian
3 месяца назад
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-defa ...
CVSS3: 6.6
github
3 месяца назад
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
EPSS
Процентиль: 43%
0.00548
Низкий
6.6 Medium
CVSS3
7.2 High
CVSS3
Дефекты
CWE-829