OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://review.openstack.org/#/c/253001 | issue tracking patch vendor advisory |
http://www.openwall.com/lists/oss-security/2015/12/03/4 | vdb entry mailing list |
https://review.openstack.org/#/c/252993 | issue tracking patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1285809 | issue tracking patch vdb entry third party advisory |