Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47211

Опубликовано: 03 окт. 2024
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

A flaw was found in OpenStack Ironic. The lack of checksum verification allows an attacker with access to the images to modify an image without the change noticed by OpenStack. This issue leads to integrity issues in the image.

Отчет

This vulnerability is classified as moderate severity rather than important because it requires a specific set of conditions for exploitation. An attacker must have access to the image source and be positioned to intercept or modify images during their transmission, which limits the attack surface to environments with insecure or untrusted network configurations. Additionally, the vulnerability only impacts Ironic when it is configured to convert images to raw format for streaming, making it a less common scenario. The absence of checksum validation could compromise image integrity, but it does not grant direct control over the system or immediate escalation of privileges, hence the moderate classification. Red Hat OpenStack 16.2 is not affected by this vulnerability, as it doesn't contain the affected code and the needed configuration option required to a successful exploit.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2openstack-ironicNot affected
Red Hat OpenShift Container Platform 4.16openshift4/ose-ironic-rhel9FixedRHSA-2024:841530.10.2024
Red Hat OpenShift Container Platform 4.17openshift4/ose-ironic-rhel9FixedRHSA-2024:822923.10.2024
Red Hat OpenStack Platform 17.1 for RHEL 9openstack-ironicFixedRHSA-2025:348207.04.2025
Red Hat OpenStack Services on OpenShift 18.0openstack-ironicFixedRHSA-2025:043922.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-354
https://bugzilla.redhat.com/show_bug.cgi?id=2315010openstack-ironic: Lack of checksum validation on images

EPSS

Процентиль: 40%
0.00184
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

CVSS3: 5.3
nvd
больше 1 года назад

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

CVSS3: 5.3
debian
больше 1 года назад

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x a ...

CVSS3: 5.3
github
больше 1 года назад

OpenStack Ironic fails to verify checksums of supplied image_source URLs

EPSS

Процентиль: 40%
0.00184
Низкий

6.3 Medium

CVSS3