OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Update ironic to 26.1.7; ironic to 29.0.6; ironic to 32.0.2; ironic to 35.0.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanOpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image affects ironic (pip), ironic (pip), ironic (pip), ironic (pip). Severity is medium. OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| ironicpip | >=17.0.0,<26.1.7 | 26.1.7 |
| ironicpip |
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Update ironic to 26.1.7; ironic to 29.0.6; ironic to 32.0.2; ironic to 35.0.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanOpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image affects ironic (pip), ironic (pip), ironic (pip), ironic (pip). Severity is medium. OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
AI coding agents often install or upgrade packages automatically in pip. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| ironicpip | >=17.0.0,<26.1.7 | 26.1.7 |
| ironicpip |
| >=27.0.0,<29.0.6 |
| 29.0.6 |
| ironicpip | >=30.0.0,<32.0.2 | 32.0.2 |
|---|
| ironicpip | >=33.0.0,<35.0.2 | 35.0.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=27.0.0,<29.0.6 |
| 29.0.6 |
| ironicpip | >=30.0.0,<32.0.2 | 32.0.2 |
|---|
| ironicpip | >=33.0.0,<35.0.2 | 35.0.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard