Home
MEDIUM: 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
17.0.0 (semver) before 26.1.7
affected
27.0.0 (semver) before 29.0.6
affected
30.0.0 (semver) before 32.0.2
affected
33.0.0 (semver) before 35.0.2
affected
Description
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Problem types
CWE-23 Relative Path Traversal
Product status
17.0.0 (semver) before 26.1.7
27.0.0 (semver) before 29.0.6
30.0.0 (semver) before 32.0.2
33.0.0 (semver) before 35.0.2
References
www.openwall.com/lists/oss-security/2026/06/03/12
bugs.launchpad.net/ironic/+bug/2148333
www.openwall.com/lists/oss-security/2026/06/03/12