In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed version details are: Ironic: <21.4.3, >=22.0.0 <23.0.2, >=23.1.0 <24.1.2, >=25.0.0 <26.0.1; Ironic-python-agent: <9.4.2, >=9.5.0 <9.7.1, >=9.8.0 <9.11.1, >=9.12.0 <9.13.1.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ironic content for Red Hat OpenShift Container Platform 4.12 | RedHat | openstack-ironic-1:21.0.1-0.20240913135525.114badc.el9 | * |
Ironic content for Red Hat OpenShift Container Platform 4.13 | RedHat | openstack-ironic-1:21.3.1-0.20240911165036.c0d61d0.el9 | * |
Red Hat OpenShift Container Platform 4.14 | RedHat | openshift4/ose-ironic-rhel9:v4.14.0-202410111109.p0.g0b1212c.assembly.stream.el9 | * |
Red Hat OpenShift Container Platform 4.15 | RedHat | openshift4/ose-ironic-rhel9:v4.15.0-202410011835.p0.gcff728e.assembly.stream.el9 | * |
Red Hat OpenShift Container Platform 4.16 | RedHat | openshift4/ose-ironic-rhel9:v4.16.0-202409202304.p0.gdd19aa0.assembly.stream.el9 | * |
Red Hat OpenStack Platform 16.2 | RedHat | openstack-ironic-1:13.0.8-2.20230713045150.d10fd5c.el8ost | * |
Red Hat OpenStack Platform 17.1 for RHEL 9 | RedHat | openstack-ironic-1:17.1.1-17.1.20240917210749.c31db88.el9ost | * |
Ironic | Ubuntu | esm-apps/jammy | * |
Ironic | Ubuntu | esm-apps/noble | * |
Ironic | Ubuntu | focal | * |
Ironic | Ubuntu | jammy | * |
Ironic | Ubuntu | noble | * |
Ironic | Ubuntu | oracular | * |
Ironic-python-agent | Ubuntu | oracular | * |