REDHAT-BUG-2466844: High severity Dell iDRAC vulnerability
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Ironic (iDRAC component referenced)to a version that resolves this vulnerability.Fixed in 26.1.6 - Upgrade
Upgrade
OpenStack Ironic (iDRAC component referenced)to a version that resolves this vulnerability.Fixed in 29.0.5 - Upgrade
Upgrade
OpenStack Ironic (iDRAC component referenced)to a version that resolves this vulnerability.Fixed in 32.0.1 - Upgrade
Upgrade
OpenStack Ironic (iDRAC component referenced)to a version that resolves this vulnerability.Fixed in 35.0.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466844?
The severity of REDHAT-BUG-2466844 is high with a score of 7.
What vulnerability does REDHAT-BUG-2466844 describe?
REDHAT-BUG-2466844 describes an issue in iDRAC of OpenStack Ironic that allows unauthorized credential forwarding during import.
How do I fix REDHAT-BUG-2466844?
To fix REDHAT-BUG-2466844, ensure that you upgrade to OpenStack Ironic version 35.0.1 or higher.
What software is affected by REDHAT-BUG-2466844?
REDHAT-BUG-2466844 affects Dell iDRAC and OpenStack Ironic software.
What consequence does REDHAT-BUG-2466844 pose to users?
The consequence of REDHAT-BUG-2466844 is that a time-limited Keystone token can be misused to access all OpenStack services that Ironic is authorized for.