CVE-2016-4985
published 2016-07-12CVE-2016-4985: The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.84%
85.0th percentile
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | openstack_ironic | <= 4.2.4 | — |
| canonical | openstack_ironic | — | — |
| canonical | openstack_ironic | — | — |
| debian | ironic | < ironic 1:5.1.2-1 (bookworm) | ironic 1:5.1.2-1 (bookworm) |
| openstack | ironic | >= 0 < 1:5.1.2-1 | 1:5.1.2-1 |
| openstack | ironic | >= 0 < 1:5.1.2-1 | 1:5.1.2-1 |
| openstack | ironic | >= 0 < 1:5.1.2-1 | 1:5.1.2-1 |
| openstack | ironic | >= 0 < 1:5.1.2-1 | 1:5.1.2-1 |
| openstack | ironic | >= 0 < 4.2.5 | 4.2.5 |
| openstack | ironic | >= 5.0 < 5.1.2 | 5.1.2 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
ghsa·2022-05-13
CVE-2016-4985 [HIGH] CWE-200 OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the `v1/drivers/$DRIVER_NAME/vendor_passthru` resource.
OSV
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
osv·2022-05-13
CVE-2016-4985 [HIGH] OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the `v1/drivers/$DRIVER_NAME/vendor_passthru` resource.
OSV
CVE-2016-4985: The ironic-api service in OpenStack Ironic before 4
osv·2016-07-12·CVSS 7.5
CVE-2016-4985 [HIGH] CVE-2016-4985: The ironic-api service in OpenStack Ironic before 4
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Red Hat
openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
vendor_redhat·2016-06-21·CVSS 7.5
CVE-2016-4985 [HIGH] CWE-290 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
An authentication vulnerability was found in openstack-ironic. A client with network access to the ironic-api service could bypass OpenStack Identity authentication, and retrieve all information about any node registered with OpenStack Bare Metal. If an unprivileged attacker knew (or was able to guess) the MAC address of a network card belonging t
Debian
CVE-2016-4985: ironic - The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before...
vendor_debian·2016·CVSS 7.5
CVE-2016-4985 [HIGH] CVE-2016-4985: ironic - The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before...
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Scope: local
bookworm: resolved (fixed in 1:5.1.2-1)
bullseye: resolved (fixed in 1:5.1.2-1)
forky: resolved (fixed in 1:5.1.2-1)
sid: resolved (fixed in 1:5.1.2-1)
trixie: resolved (fixed in 1:5.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [fedora-all]
bugzilla·2016-06-22·CVSS 7.5
CVE-2016-4985 [HIGH] CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [fedora-all]
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [openstack-rdo]
bugzilla·2016-06-22·CVSS 7.5
CVE-2016-4985 [HIGH] CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [openstack-rdo]
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users [openstack-rdo]
This as an RDO Project security tracking bug against openstack-ironic. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Hi Alan!
Could you please rebase Ironic on all supported branches to fix this CVE? The versions are: Liberty - 4.2.5, Mitaka - 5.1.2, Newton - 6.0.0 (probably not needed).
---
Newton is continuously built in RDO Trunk master repo, I'll build liberty and newton in CBS.
Bugzilla
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
bugzilla·2016-06-14·CVSS 7.5
CVE-2016-4985 [HIGH] CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
CVE-2016-4985 openstack-ironic: Ironic Node information including credentials exposed to unauthenticated users
A client with network access to the ironic-api service can bypass Keystone authentication and retrieve all information about any Node registered with Ironic, if they know (or are able to guess) the MAC address of a network card belonging to that Node, by sending a crafted POST request to the /v1/drivers/$DRIVER_NAME/vendor_passthru resource.
The response will include the full Node details, including management passwords, even when /etc/ironic/policy.json is configured to hide passwords in API responses.
This vulnerability has been verified in all currently supported branches (liberty, mitaka, master) and traced back to code introduced in commit 3e568fbbbcc5748035c1448a0bdb26306
http://www.openwall.com/lists/oss-security/2016/06/21/6https://access.redhat.com/errata/RHSA-2016:1377https://access.redhat.com/errata/RHSA-2016:1378https://bugs.launchpad.net/ironic/+bug/1572796https://review.openstack.org/332195https://review.openstack.org/332196https://review.openstack.org/332197http://www.openwall.com/lists/oss-security/2016/06/21/6https://access.redhat.com/errata/RHSA-2016:1377https://access.redhat.com/errata/RHSA-2016:1378https://bugs.launchpad.net/ironic/+bug/1572796https://review.openstack.org/332195https://review.openstack.org/332196https://review.openstack.org/332197
2016-07-12
Published