CVE-2026-90461
6.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Summary
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenStack | Ironic | 24.0.0 <= 29.0.6 | affected |
| OpenStack | Ironic | 30.0.0 <= 32.0.1 | affected |
| OpenStack | Ironic | 33.0.0 <= 35.0.1 | affected |
| OpenStack | Ironic | 36.0.0 <= 38.0.0 | affected |
Weaknesses
- CWE-923: CWE-923 Improper Restriction of Communication Channel to Intended Endpoints
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.