CVE Vulnerabilities

CVE-2015-5306

Published: Nov 25, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6 IMPORTANT
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

Affected Software

NameVendorStart VersionEnd Version
Ironic_inspectorOpenstack**
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatopenstack-ironic-discoverd-0:0.2.5-2.el7ost*
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7RedHatopenstack-ironic-discoverd-0:1.1.0-8.el7ost*

References