CVE Vulnerabilities

CVE-2024-47211

Published: Oct 04, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

Affected Software

NameVendorStart VersionEnd Version
Red Hat OpenShift Container Platform 4.16RedHatopenshift4/ose-ironic-rhel9:v4.16.0-202410221305.p0.g38becaa.assembly.stream.el9*
Red Hat OpenShift Container Platform 4.17RedHatopenshift4/ose-ironic-rhel9:v4.17.0-202410161235.p0.g90a9bc5.assembly.stream.el9*
Red Hat OpenStack Platform 17.1 for RHEL 9RedHatopenstack-ironic-1:17.1.1-17.1.20241122190825.c31db88.el9ost*
Red Hat OpenStack Services on OpenShift 18.0RedHatopenstack-ironic-1:21.4.5-18.0.20241207142602.9213ccd.el9ost*
IronicUbuntufocal*
IronicUbuntuoracular*
IronicUbuntuplucky*
IronicUbuntuupstream*

References