PT-2026-49105 · Openstack · Openstack Ironic
Published
2026-06-14
·
Updated
2026-06-14
·
CVE-2026-54421
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Ironic versions prior to 35.0.2
Description
When applying a PATCH request to update fields in volume properties for which a user is authorized, the system may return unredacted sensitive information, such as iSCSI credentials. This issue specifically occurs during the PATCH operation, whereas the POST operation does not result in this disclosure.
Recommendations
Update to version 35.0.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Ironic