Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
OpenStack Bare Metal (ironic) is a tool used to provision bare metal
(as opposed to virtual) machines. It leverages common technologies such
as PXE boot and IPMI to cover a wide range of hardware. It also supports
pluggable drivers to allow added, vendor-specific functionality.
It was discovered that enabling debug mode in openstack-ironic-discoverd
also enabled debug mode in the underlying Flask framework. If errors were
encountered while Flask was in debug mode, a user experiencing an error
might be able to access the debug console (effectively, a command shell).
(CVE-2015-5306)
Please note that this package is a Technology Preview and should not be
used in production.
All openstack-ironic-discoverd users are advised to upgrade to these
updated packages, which correct this issue.
https://access.redhat.com/security/cve/CVE-2015-5306 https://access.redhat.com/security/updates/classification#important
Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7:
Source:
openstack-ironic-discoverd-0.2.5-2.el7ost.src.rpm
noarch:
openstack-ironic-discoverd-0.2.5-2.el7ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key
Updated openstack-ironic-discoverd packages that fix one security issue arenow available for Red Hat Enterprise Linux OpenStack Platform 6.0.Red Hat Product Security has rated this update as having Important securityimpact. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available from the CVE link in theReferences section.
Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7 - noarch
1273698 - CVE-2015-5306 openstack-ironic-discoverd: potential remote code execution with debug mode enabled
Get the latest Linux and open source security news straight to your inbox.