Description
OpenStack Ironic fails to verify checksums of supplied image_source URLs
In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 | - |
 debian 11 | | =1:16.0.3-1 || =1:16.2.0-1 || =1:17.0.0-1 || =1:17.0.1-1 || =1:17.0.3-1 || =1:17.0.3-2 || =1:18.1.0-1 || =1:18.2.0-1 || =1:18.2.0-2 || =1:18.2.0-3 || =1:20.0.0-1 || =1:20.1.0-1 || =1:20.1.0-2 || =1:21.0.0-1 || =1:21.0.0-2 || =1:21.0.0-3 || =1:21.1.0-1 || =1:21.1.0-2 || =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 | - |
 debian 13 | | | 1:26.1.0-1 |
 pypi | | >=25.0.0 <26.1.1 || >=23.1.0 <24.1.3 || >=22.0.0 <23.0.3 || >=0 <=21.4.3 | 26.1.1, 24.1.3, 23.0.3 |
 debian 14 | | | 1:26.1.0-1 |