Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-54w4-233h-x86g | OpenStack Ironic has an Incorrect Resource Transfer Between Spheres |
Wed, 06 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-06T06:12:45.933Z
Reserved: 2026-05-01T00:00:00.000Z
Link: CVE-2026-42997
Updated: 2026-05-05T19:32:05.605Z
Status : Awaiting Analysis
Published: 2026-05-05T19:16:22.817
Modified: 2026-05-07T15:53:49.717
Link: CVE-2026-42997
No data.
OpenCVE Enrichment
Updated: 2026-05-05T19:30:30Z
Github GHSA