VDB
KO
MEDIUM 5.3

GHSA-8h22-6qwx-q4w9

OpenStack Ironic fails to verify checksums of supplied image_source URLs

Details

In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / ironic
Introduced in: 25.0.0 Fixed in: 26.1.1
Fix pip install --upgrade 'ironic>=26.1.1'
PyPI / ironic
Introduced in: 23.1.0 Fixed in: 24.1.3
Fix pip install --upgrade 'ironic>=24.1.3'
PyPI / ironic
Introduced in: 22.0.0 Fixed in: 23.0.3
Fix pip install --upgrade 'ironic>=23.0.3'
PyPI / ironic
Introduced in: 0

No fixed version published yet for ironic (pip). Pin to a known-safe version or switch to an alternative.

References