cbcvebase.
CVE-2016-4985
published 2016-07-12

CVE-2016-4985: The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a…

high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalopenstack_ironic<= 4.2.4
canonicalopenstack_ironic
canonicalopenstack_ironic
debianironic< ironic 1:5.1.2-1 (bookworm)ironic 1:5.1.2-1 (bookworm)
openstackironic>= 0 < 1:5.1.2-11:5.1.2-1
openstackironic>= 0 < 1:5.1.2-11:5.1.2-1
openstackironic>= 0 < 1:5.1.2-11:5.1.2-1
openstackironic>= 0 < 1:5.1.2-11:5.1.2-1
openstackironic>= 0 < 4.2.54.2.5
openstackironic>= 5.0 < 5.1.25.1.2
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH