Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48681

Опубликовано: 04 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

A flaw was found in OpenStack Ironic (before 35.0.2). A directory traversal vulnerability during deployment allows an attacker to overwrite files on the system when a crafted ISO image is used. This can compromise confidentiality and integrity of files on the deployment target.

Отчет

OpenStack Ironic is vulnerable to directory traversal during node deployment when processing a crafted ISO image, allowing file overwrite on the target system. A remote attacker with high privileges who can initiate deployments with attacker-controlled ISO content could read or modify files (confidentiality and integrity impact). Affects OpenStack 16.2, 17.1, 18.0, and OpenShift-embedded openstack-ironic RPM streams.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openstack-ironicFix deferred
Red Hat OpenStack Platform 16.2openstack-ironicFix deferred
Red Hat OpenStack Platform 17.1openstack-ironicFix deferred
Red Hat OpenStack Platform 18.0openstack-ironicFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2484608openstack-ironic: OpenStack Ironic: File overwrite via directory traversal vulnerability

EPSS

Процентиль: 45%
0.00601
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
2 месяца назад

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

CVSS3: 5.9
nvd
2 месяца назад

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

CVSS3: 5.9
debian
2 месяца назад

OpenStack Ironic through before 35.0.2 allows file overwrite via direc ...

CVSS3: 5.9
github
2 месяца назад

OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image

EPSS

Процентиль: 45%
0.00601
Низкий

5.9 Medium

CVSS3