Improper validation of integrity check value in OpenStack Ironic - CVE-2024-47211
Published: October 8, 2024
Vulnerability identifier: #VU98123
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47211
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming. A remote attacker can perform MitM attack.
Affected software
OpenStack Ironic
Red Hat OpenShift Container Platform
Red Hat OpenStack
openstack-ironic (Red Hat package)
Red Hat OpenShift Container Platform
Red Hat OpenStack
openstack-ironic (Red Hat package)
How to mitigate CVE-2024-47211
Install updates from vendor's website.
OpenStack Ironic - addressed in versions 21.4.4, 23.0.3, 24.1.3, 26.1.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.19, 4.17.2
Red Hat OpenStack - addressed in versions 17.1, 18.0.4
openstack-ironic (Red Hat package) - addressed in versions 17.1.1-17.1.20241122190825.c31db88.el9ost, 21.4.5-18.0.20241207142602.9213ccd.el9ost
Red Hat OpenShift Container Platform - addressed in versions 4.16.19, 4.17.2
Red Hat OpenStack - addressed in versions 17.1, 18.0.4
openstack-ironic (Red Hat package) - addressed in versions 17.1.1-17.1.20241122190825.c31db88.el9ost, 21.4.5-18.0.20241207142602.9213ccd.el9ost
External References
Related Security Bulletins
- Improper access control in OpenStack Ironic
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Improper validation of integrity check value in Red Hat OpenStack 18.0 packages
- Improper validation of integrity check value in Red Hat OpenStack 17.1 packages