Описание
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
A flaw was found in OpenStack ironic-python-agent's bootc container deployment support. During bootc image deployment, the OCI registry pull secret was exposed to tenant-controlled container code running with host PID namespace visibility. A malicious bootc container image could read the operator's registry credentials from the host filesystem via /proc/1/root, leading to credential disclosure. This could allow a project-scoped tenant to extract shared operator registry credentials, potentially affecting multiple nodes and projects.
Отчет
Red Hat OpenStack Platform ships ironic-python-agent as part of its bare metal provisioning infrastructure. Deployments that use the bootc deploy_interface are affected by this vulnerability when operator-sourced registry pull secrets are used. Deployments that do not use the bootc deploy_interface, or that do not use authenticated container registries, are not affected. The bootc deployment feature was introduced in more recent versions of ironic-python-agent. Older versions of Red Hat OpenStack Platform that ship ironic-python-agent versions prior to 10.2.0 are not affected as they do not contain bootc deployment support.
Меры по смягчению последствий
Operators can disable the bootc deploy_interface on their Ironic conductors by setting 'disable_bootc_deploy = true' in the ironic-python-agent configuration. Additionally, operators should avoid using operator-sourced registry pull secrets (driver_info.image_pull_secret or [deploy] image_server_user/password) with the bootc deploy_interface until the fix is applied. If the bootc deploy_interface must remain enabled, restrict which users can deploy arbitrary container images by limiting access to the baremetal provisioning API.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-ironic-agent-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openstack-ironic-python-agent | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | openstack-ironic-python-agent | Not affected | ||
| Red Hat OpenStack Platform 17.1 | openstack-ironic-python-agent | Not affected | ||
| Red Hat OpenStack Platform 18.0 | openstack-ironic-python-agent | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
EPSS
6.5 Medium
CVSS3