cbcvebase.
CVE-2024-47211
published 2024-10-04

CVE-2024-47211: In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum…

PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.66%
47.4th percentile
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianironic< ironic 1:26.1.0-1 (forky)ironic 1:26.1.0-1 (forky)
linuxlinux_kernel>= 0 < 4.4.0-269.3034.4.0-269.303
linuxlinux_kernel>= 0 < 4.15.0-238.2504.15.0-238.250
openstackironic>= 0 < 1:26.1.0-11:26.1.0-1
openstackironic>= 0 < 1:26.1.0-11:26.1.0-1
openstackironic0 – 21.4.3
openstackironic>= 22.0.0 < 23.0.323.0.3
openstackironic>= 23.1.0 < 24.1.324.1.3
openstackironic>= 25.0.0 < 26.1.126.1.1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.