OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Description
Published by the National Vulnerability Database
Jul 12, 2016
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 14, 2024
Last updated
May 14, 2024
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the
v1/drivers/$DRIVER_NAME/vendor_passthru
resource.References