GHSA-wqpv-c3pp-3m58MediumCVSS 6.6

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

Published
April 28, 2026
Last Modified
July 8, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

🎯 Affected products1

  • pip/ironic:< 35.0.1

🔗 References (5)