OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
References
| Link | Resource |
|---|---|
| https://bugs.launchpad.net/ironic/+bug/2150624 | Issue Tracking |
| https://security.openstack.org/ossa/OSSA-2026-017.html | Patch Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/03/11 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/15/9 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-03 22:16
Updated : 2026-07-22 20:10
NVD link : CVE-2026-46447
Mitre link : CVE-2026-46447
CVE.ORG link : CVE-2026-46447
JSON object : View
Products Affected
openstack
- ironic
CWE
CWE-669
Incorrect Resource Transfer Between Spheres
