Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8h22-6qwx-q4w9 | OpenStack Ironic fails to verify checksums of supplied image_source URLs |
Tue, 08 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openstack:17.1::el9 |
Thu, 13 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openstack
|
|
| CPEs | cpe:/a:redhat:openstack:18.0::el9 | |
| Vendors & Products |
Redhat openstack
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 30 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.16::el9 |
Wed, 23 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat openshift |
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| Vendors & Products |
Redhat
Redhat openshift |
Tue, 08 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | openstack-ironic: Lack of checksum validation on images | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 04 Oct 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-05T15:06:00.808Z
Reserved: 2024-09-21T00:00:00.000Z
Link: CVE-2024-47211
Updated: 2024-10-05T23:03:03.995Z
Status : Deferred
Published: 2024-10-04T18:15:08.550
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-47211
OpenCVE Enrichment
No data.
Github GHSA