CVE-2019-10141
Description
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspectors node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector 5.0.2 | Windows |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector 6.0.3 | Windows |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector 7.2.4 | Windows |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector 8.0.3 | Windows |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector 8.2.1 | Windows |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector for linux 5.0.2 | Linux |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector for linux 6.0.3 | Linux |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector for linux 7.2.4 | Linux |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector for linux 8.0.3 | Linux |
| Vulnerabilities CVE-2019-10141 are fixed in Python-ironic-inspector for linux 8.2.1 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234