GHSA-8h22-6qwx-q4w9

Suggest an improvement
Source
https://github.com/advisories/GHSA-8h22-6qwx-q4w9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-8h22-6qwx-q4w9/GHSA-8h22-6qwx-q4w9.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-8h22-6qwx-q4w9
Aliases
Published
2024-10-04T18:31:11Z
Modified
2024-11-05T18:51:37.366806Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Details

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

Database specific
{
    "nvd_published_at": "2024-10-04T18:15:08Z",
    "cwe_ids": [
        "CWE-354"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-04T20:31:16Z"
}
References

Affected packages

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
25.0.0
Fixed
26.1.1

Affected versions

25.*

25.0.0

26.*

26.0.0
26.1.0

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
23.1.0
Fixed
24.1.3

Affected versions

23.*

23.1.0

24.*

24.0.0
24.1.0
24.1.1
24.1.2

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
22.0.0
Fixed
23.0.3

Affected versions

22.*

22.0.0
22.1.0

23.*

23.0.0
23.0.1
23.0.2

PyPI / ironic

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
21.4.3

Affected versions

0.*

0.0

9.*

9.1.6
9.1.7

10.*

10.1.7
10.1.8
10.1.9
10.1.10

11.*

11.1.1
11.1.2
11.1.3
11.1.4

12.*

12.0.0
12.1.0
12.1.1
12.1.2
12.1.3
12.1.4
12.1.5
12.1.6
12.2.0

13.*

13.0.0
13.0.1
13.0.2
13.0.3
13.0.4
13.0.5
13.0.6
13.0.7

14.*

14.0.0

15.*

15.0.0
15.0.1
15.0.2
15.1.0
15.2.0

16.*

16.0.0
16.0.1
16.0.2
16.0.3
16.0.4
16.0.5
16.1.0
16.2.0

17.*

17.0.0
17.0.1
17.0.2
17.0.3
17.0.4
17.1.0

18.*

18.0.0
18.1.0
18.2.0
18.2.1
18.2.2
18.3.0

19.*

19.0.0

20.*

20.0.0
20.1.0
20.1.1
20.1.2
20.1.3
20.2.0

21.*

21.0.0
21.1.0
21.1.1
21.1.2
21.2.0
21.3.0
21.4.0
21.4.1
21.4.2
21.4.3