Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5306

Опубликовано: 15 окт. 2015
Источник: redhat
CVSS2: 6

Описание

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

It was discovered that enabling debug mode in openstack-ironic-discoverd also enabled debug mode in the underlying Flask framework. If errors were encountered while Flask was in debug mode, a user experiencing an error might be able to access the debug console (effectively, a command shell).

Дополнительная информация

Статус:

Important
Дефект:
CWE-749
https://bugzilla.redhat.com/show_bug.cgi?id=1273698openstack-ironic-discoverd: potential remote code execution with debug mode enabled

6 Medium

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

debian
около 10 лет назад

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), ...

CVSS3: 8.1
github
больше 6 лет назад

Injection vulnerability that affects ironic-discoverd

6 Medium

CVSS2