OpenStack Ironic
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*
- >= 27.0.0, < 29.0.6
- >= 30.0.0, < 32.0.2
- >= 33.0.0, < 35.0.2
- >= 36.0.0, < 37.0.1
A vulnerability exists in OpenStack Ironic versions prior to 37.0.1, allowing unauthorized cross-project creation or modification of nodes. This issue arises from inadequate role-based access control (RBAC) checks, enabling project managers to manipulate node associations with Volume Connectors or Volume Targets, potentially altering access permissions for sensitive data, particularly in environments using iSCSI for boot volumes. Additionally, project managers can exploit this vulnerability by reparenting nodes to disrupt normal operations, such as power management, on parent nodes.
Exploitation of this vulnerability can lead to unauthorized access to sensitive information contained in Volume Connectors, as well as disruption of node management operations, particularly in relation to power controls and instance provisioning through the Nova driver.
To reproduce this vulnerability, an authenticated project manager must create a node and assign it a parent node from a different project, bypassing the ownership verification. This can be done by using the UUID of a node not owned by the project, effectively creating a child node that can interfere with the parent's operations. Additionally, reparenting nodes with mismatched owners can be done through the Ironic API, which will disrupt normal power management processes.
Users can update to Ironic versions 37.0.1 or later, where this vulnerability has been addressed. Instructions for applying the update can be found in the OpenStack Ironic documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.