CVE-2016-4985: Canonical Openstack Ironic
High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
Affected products
- Canonical Openstack Ironic: up to and including 4.2.4; version 5.1.0 only; version 5.1.1 only
- Red Hat Openstack: version 7.0 only; version 8 only
Published 2016-07-12. Last modified 2026-06-17.