Description
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3715 | The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource. |
Github GHSA |
GHSA-f7cr-7c2c-fm8r | OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T00:46:39.912Z
Reserved: 2016-05-24T00:00:00.000Z
Link: CVE-2016-4985
No data.
Status : Modified
Published: 2016-07-12T19:59:04.303
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-4985
OpenCVE Enrichment
No data.
EUVD
Github GHSA