GHSA-j4cw-mcg2-2q78MediumCVSS 6.8

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

Published
June 14, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

🎯 Affected products4

  • pip/ironic:>= 17.0.0, < 29.0.6
  • pip/ironic:>= 30.0.0, < 32.0.2
  • pip/ironic:>= 33.0.0, < 35.0.2
  • pip/ironic:>= 36.0.0, < 37.0.1

🔗 References (7)