CVE-2019-10141

Description

A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.

Category

8.3
CVSS
Severity: High
CVSS 3.0 •
CVSS 2.0 •
EPSS 0.63%
Vendor Advisory redhat.com Vendor Advisory openstack.org Vendor Advisory openstack.org Vendor Advisory openstack.org Vendor Advisory openstack.org Vendor Advisory openstack.org
Affected: RedHat openstack-ironic-inspector
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2019-10141?
CVE-2019-10141 has been scored as a high severity vulnerability.
How to fix CVE-2019-10141?
To fix CVE-2019-10141, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2019-10141 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2019-10141 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2019-10141?
CVE-2019-10141 affects RedHat openstack-ironic-inspector.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.