PT-2026-46840 · Openstack · Openstack Ironic
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenStack Ironic versions 32 through 35.0.1
Description
An unauthenticated malicious user can cause a service crash by submitting a crafted JSON string to certain endpoints on the API or JSON-RPC service.
Recommendations
Update OpenStack Ironic to a version later than 35.0.1.
Exploit
Fix
DoS
Deserialization of Untrusted Data
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Ironic