REDHAT-BUG-2464306: High severity Openstack Ironic-python-agent vulnerability
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464306?
The severity of REDHAT-BUG-2464306 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2464306?
To mitigate REDHAT-BUG-2464306, ensure that you update to the latest version of OpenStack Ironic Python Agent, where this vulnerability has been addressed.
What versions are affected by REDHAT-BUG-2464306?
REDHAT-BUG-2464306 affects OpenStack Ironic Python Agent versions from 1.0.0 through 11.5.0.
What is the risk associated with REDHAT-BUG-2464306?
The risk associated with REDHAT-BUG-2464306 involves potential code execution vulnerability if a malicious image is deployed.
Can I exploit REDHAT-BUG-2464306 to execute arbitrary code?
Yes, if a malicious image is used, REDHAT-BUG-2464306 permits execution of arbitrary code through grub-install executed within a chroot environment.