Description
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =1:29.0.0-7 || =1:29.0.5-0+deb13u1 || >=0 <1:29.0.5-0+deb13u2 | 1:29.0.5-0+deb13u2 |
 debian 12 | | =1:21.1.0-3 || =1:21.1.0-3+deb12u1 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || >=0 <1:21.4.4-0+deb12u1 | 1:21.4.4-0+deb12u1 |
 debian 14 | | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 || >=0 <1:35.0.1-5 | 1:35.0.1-5 |