Description
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | ironic | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 debian 11 | ironic | =1:16.0.3-1 || =1:16.2.0-1 || =1:17.0.0-1 || =1:17.0.1-1 || =1:17.0.3-1 || =1:17.0.3-2 || =1:18.1.0-1 || =1:18.2.0-1 || =1:18.2.0-2 || =1:18.2.0-3 || =1:20.0.0-1 || =1:20.1.0-1 || =1:20.1.0-2 || =1:21.0.0-1 || =1:21.0.0-2 || =1:21.0.0-3 || =1:21.1.0-1 || =1:21.1.0-2 || =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 debian 14 | ironic | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || >=0 <1:35.0.1-1 | 1:35.0.1-1 |
 debian 12 | ironic | =1:21.1.0-3 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 | - |
 pypi | ironic-python-agent | >=33.0.0 <35.0.1 || >=30.0.0 <32.0.1 || >=27.0.0 <29.0.5 || >=0 <26.1.6 | 35.0.1, 32.0.1, 29.0.5, 26.1.6 |