Description
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =1:29.0.0-7 || =1:29.0.5-0+deb13u1 || =1:29.0.5-0+deb13u2 || >=0 <1:29.0.5-0+deb13u3 | 1:29.0.5-0+deb13u3 |
 debian 12 | | =1:21.1.0-3 || =1:21.1.0-3+deb12u1 || =1:21.3.0-1 || =1:21.4.0-1 || =1:21.4.0-2 || =1:21.4.0-3 || =1:21.4.0-4 || =1:21.4.4-0+deb12u1 || =1:21.4.4-0+deb12u2 || =1:22.1.0-1 || =1:23.0.0-1 || =1:23.0.0-2 || =1:23.0.0-3 || =1:23.0.0-4 || =1:24.0.0-1 || =1:24.1.0-1 || =1:24.1.1-1 || =1:24.1.1-2 || =1:24.1.1-3 || =1:26.0.0-1 || =1:26.0.0-2 || =1:26.1.0-1 || =1:26.1.0-2 || =1:26.1.0-3 || =1:26.1.1-1 || =1:26.1.1-2 || =1:26.1.1-3 || =1:26.1.1-4 || =1:29.0.0-1 || =1:29.0.0-2 || =1:29.0.0-3 || =1:29.0.0-4 || =1:29.0.0-5 || =1:29.0.0-6 || =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-10 || =1:35.0.1-2 || =1:35.0.1-3 || =1:35.0.1-5 || =1:35.0.1-6 || =1:35.0.1-7 || =1:35.0.1-8 || =1:35.0.1-9 || =1:38.0.0-1 || =1:38.0.0-2 | - |
 debian 14 | | =1:29.0.0-7 || =1:32.0.0-1 || =1:32.0.0-2 || =1:32.0.0-4 || =1:32.0.0-5 || =1:32.0.0-6 || =1:32.0.0-7 || =1:34.0.0-1 || =1:35.0.0-1 || =1:35.0.0-2 || =1:35.0.1-1 || =1:35.0.1-2 || =1:35.0.1-3 || =1:35.0.1-5 || =1:35.0.1-6 || =1:35.0.1-7 || >=0 <1:35.0.1-8 | 1:35.0.1-8 |