CVE-2015-7514
published 2017-06-07CVE-2015-7514: OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.58%
72.6th percentile
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ironic | < ironic 1:4.2.2-1 (bookworm) | ironic 1:4.2.2-1 (bookworm) |
| openstack | ironic | — | — |
| openstack | ironic | — | — |
| openstack | ironic | >= 0 < 1:4.2.2-1 | 1:4.2.2-1 |
| openstack | ironic | >= 0 < 1:4.2.2-1 | 1:4.2.2-1 |
| openstack | ironic | >= 0 < 1:4.2.2-1 | 1:4.2.2-1 |
| openstack | ironic | >= 0 < 1:4.2.2-1 | 1:4.2.2-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xh73-4jm2-j7c9: OpenStack Ironic 4
ghsa_unreviewed·2022-05-17
CVE-2015-7514 [MEDIUM] CWE-200 GHSA-xh73-4jm2-j7c9: OpenStack Ironic 4
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
OSV
CVE-2015-7514: OpenStack Ironic 4
osv·2017-06-07·CVSS 6.5
CVE-2015-7514 [MEDIUM] CVE-2015-7514: OpenStack Ironic 4
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Red Hat
openstack-ironic: Ironic does not honor clean steps
vendor_redhat·2015-12-03·CVSS 6.5
CVE-2015-7514 [MEDIUM] openstack-ironic: Ironic does not honor clean steps
openstack-ironic: Ironic does not honor clean steps
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Package: openstack-ironic (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: openstack-ironic (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: openstack-ironic (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Director) - Not affected
Package: openstack-ironic (Red Hat OpenStack Platform 8 (Liberty)) - Not affected
Debian
CVE-2015-7514: ironic - OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which ...
vendor_debian·2015·CVSS 6.5
CVE-2015-7514 [MEDIUM] CVE-2015-7514: ironic - OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which ...
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 1:4.2.2-1)
bullseye: resolved (fixed in 1:4.2.2-1)
forky: resolved (fixed in 1:4.2.2-1)
sid: resolved (fixed in 1:4.2.2-1)
trixie: resolved (fixed in 1:4.2.2-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2015/12/03/4https://bugzilla.redhat.com/show_bug.cgi?id=1285809https://review.openstack.org/#/c/252993https://review.openstack.org/#/c/253001http://www.openwall.com/lists/oss-security/2015/12/03/4https://bugzilla.redhat.com/show_bug.cgi?id=1285809https://review.openstack.org/#/c/252993https://review.openstack.org/#/c/253001
2017-06-07
Published