Description
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
References (3)
Core 3
Scores
CVSS v3
7.7
EPSS
0.0001
EPSS Percentile
1.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-669
Status
published
Products (8)
OpenStack/Ironic
17.0.0 - 26.1.6
OpenStack/Ironic
27.0.0 - 29.0.5
OpenStack/Ironic
30.0.0 - 32.0.1
OpenStack/Ironic
33.0.0 - 35.0.1
pypi/ironic-python-agent
0 - 26.1.6PyPI
pypi/ironic-python-agent
27.0.0 - 29.0.5PyPI
pypi/ironic-python-agent
30.0.0 - 32.0.1PyPI
pypi/ironic-python-agent
33.0.0 - 35.0.1PyPI
Published
May 05, 2026
Tracked Since
May 06, 2026