REDHAT-BUG-2485353: High severity Openstack Ironic vulnerability
In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2485353?
The severity of REDHAT-BUG-2485353 is categorized as high with a score of 7.
How does REDHAT-BUG-2485353 affect OpenStack Ironic?
REDHAT-BUG-2485353 allows an unauthenticated malicious user to crash the service by submitting a crafted JSON string to certain API endpoints.
What versions of OpenStack Ironic are impacted by REDHAT-BUG-2485353?
OpenStack Ironic versions 32 through 35.0.1 are affected by REDHAT-BUG-2485353.
How can I mitigate the risks associated with REDHAT-BUG-2485353?
To mitigate REDHAT-BUG-2485353, it's recommended to upgrade to a patched version of OpenStack Ironic that addresses this vulnerability.
What kind of attacks can be executed due to REDHAT-BUG-2485353?
Due to REDHAT-BUG-2485353, an attacker can execute denial-of-service attacks by exploiting vulnerabilities in the API and JSON-RPC service.