CVE-2026-44916
נמוכה 3.0
תיאור (מקור, אנגלית)
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
מדדים
- CVSS 3.1
-
3.0 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/8/2026
- CWE
- CWE-1336
מוצרים מושפעים
openstack: ironic
קישורים
- https://security.openstack.org/ossa/OSSA-2026-012.html PatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/05/11/7 Mailing ListPatchThird Party Advisory
- https://bugs.launchpad.net/ironic/+bug/2148307 Issue TrackingMitigationThird Party Advisory