CVE Vulnerabilities

CVE-2015-5306

Published: Nov 25, 2015 | Modified: Feb 12, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6 IMPORTANT
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

Affected Software

Name Vendor Start Version End Version
Ironic_inspector Openstack * *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat openstack-ironic-discoverd-0:0.2.5-2.el7ost *
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 RedHat openstack-ironic-discoverd-0:1.1.0-8.el7ost *

References