⚠️ Metal3 Ironic image security bug

10 views
Skip to first unread message

feruzjon....@est.tech

unread,
Sep 6, 2021, 4:24:42 PM9/6/21
to Metal3 Development List
Hi,

We have identified a security bug in Metal3 Ironic container image which allowed unauthenticated users to access Ironic endpoints. This issue is rated moderate severity and fix is made in https://github.com/metal3-io/ironic-image/pull/297.  A new container image with above fix is now available in Quay: https://quay.io/repository/metal3-io/ironic. 

Best regards,
Feruzjon Muyassarov
Reply all
Reply to author
Forward
0 new messages