In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugs.launchpad.net/ironic/+bug/2155049 |
|
History
Sun, 14 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ironic Unredacted Credentials via Volume Properties PATCH |
Sun, 14 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-212 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-14T03:49:37.996Z
Reserved: 2026-06-14T03:49:37.600Z
Link: CVE-2026-54421
No data.
Status : Received
Published: 2026-06-14T04:16:30.927
Modified: 2026-06-14T04:16:30.927
Link: CVE-2026-54421
No data.
OpenCVE Enrichment
Updated: 2026-06-14T05:30:07Z