Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
敏感数据的不恰当跨边界移除
Vulnerability Title
OpenStack Ironic 信息泄露漏洞
Vulnerability Description
OpenStack ironic是OpenStack基金会开源的一个裸金属服务管理组件。 OpenStack Ironic 35.0.1及之前版本存在信息泄露漏洞,该漏洞源于当授权用户通过PATCH更新卷属性中的字段时,Ironic会返回未脱敏的敏感信息(如iSCSI凭据),可能导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A