OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2015:1929 | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-2685.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1273698 | vendor advisory |
https://bugs.launchpad.net/ironic-inspector/+bug/1506419 | vendor advisory |