REDHAT-BUG-2315010: Medium severity Openstack Ironic vulnerability
Published Sep 26, 2024
·Updated
There's a flaw in Ironic where images may not have their checksum validated before conversion, potentially permitting man-in-the-middle attacks modifying image data.
Affected Software
1 affected component
Openstack Ironic
Event History
Sep 26, 2024
Data Sourced
via Red Hat·08:20 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2315010?
The severity of REDHAT-BUG-2315010 is classified as medium with a score of 4.
2
What is the main issue described in REDHAT-BUG-2315010?
The main issue in REDHAT-BUG-2315010 is that Ironic may not validate image checksums before conversion, which could allow man-in-the-middle attacks.
3
How can I remediate REDHAT-BUG-2315010?
To remediate REDHAT-BUG-2315010, ensure that Ironic is configured to validate image checksums before conversion.
4
Which software is affected by REDHAT-BUG-2315010?
OpenStack Ironic is the software affected by REDHAT-BUG-2315010.
5
When was REDHAT-BUG-2315010 published?
REDHAT-BUG-2315010 was published on September 26, 2024.