Lack of data validation In python-ironic-inspector-client
Description
Injection vulnerability that affects ironic-discoverd OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 0.2.5 | ||
pypi | 2.2.2 | ||
pypi | 0.2.5 | ||
debian 11 | 3.2.0-1 | ||
debian 13 | 3.2.0-1 | ||
debian 12 | 3.2.0-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6.