4
CVSSv2

CVE-2015-7514

Published: 07/06/2017 Updated: 14/06/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

OpenStack Ironic 4.2.0 up to and including 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack ironic 4.2.1

openstack ironic 4.2.0

Vendor Advisories

Debian Bug report logs - #807269 ironic: CVE-2015-7514: Ironic does not honor clean steps Package: src:ironic; Maintainer for src:ironic is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 6 Dec 2015 21:21:01 UTC Severity: important Tags: patch, s ...
OpenStack Ironic 420 through 421 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information ...