Описание
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
A flaw was found in OpenStack Ironic (before 35.0.2). A directory traversal vulnerability during deployment allows an attacker to overwrite files on the system when a crafted ISO image is used. This can compromise confidentiality and integrity of files on the deployment target.
Отчет
OpenStack Ironic is vulnerable to directory traversal during node deployment when processing a crafted ISO image, allowing file overwrite on the target system. A remote attacker with high privileges who can initiate deployments with attacker-controlled ISO content could read or modify files (confidentiality and integrity impact). Affects OpenStack 16.2, 17.1, 18.0, and OpenShift-embedded openstack-ironic RPM streams.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 17.1 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 18.0 | openstack-ironic | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
OpenStack Ironic through before 35.0.2 allows file overwrite via direc ...
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
EPSS
5.9 Medium
CVSS3