Vulnerability Details CVE-2019-10141
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 8.3
CVSS v2 Score 6.4
Products affected by CVE-2019-10141
-
cpe:2.3:a:openstack:ironic-inspector:-
-
cpe:2.3:a:openstack:ironic-inspector:5.0.0
-
cpe:2.3:a:openstack:ironic-inspector:5.0.1
-
cpe:2.3:a:openstack:ironic-inspector:5.1.0
-
cpe:2.3:a:openstack:ironic-inspector:6.0.0
-
cpe:2.3:a:openstack:ironic-inspector:6.0.1
-
cpe:2.3:a:openstack:ironic-inspector:6.0.2
-
cpe:2.3:a:openstack:ironic-inspector:6.1.0
-
cpe:2.3:a:openstack:ironic-inspector:7.0.0
-
cpe:2.3:a:openstack:ironic-inspector:7.1.0
-
cpe:2.3:a:openstack:ironic-inspector:7.2.0
-
cpe:2.3:a:openstack:ironic-inspector:7.2.1
-
cpe:2.3:a:openstack:ironic-inspector:7.2.2
-
cpe:2.3:a:openstack:ironic-inspector:7.2.3
-
cpe:2.3:a:openstack:ironic-inspector:8.0.0
-
cpe:2.3:a:openstack:ironic-inspector:8.0.1
-
cpe:2.3:a:openstack:ironic-inspector:8.0.2
-
cpe:2.3:a:openstack:ironic-inspector:8.1.0
-
cpe:2.3:a:openstack:ironic-inspector:8.2.0
-
cpe:2.3:a:redhat:openstack:10
-
cpe:2.3:a:redhat:openstack:13
-
cpe:2.3:a:redhat:openstack:14
-
cpe:2.3:a:redhat:openstack:9
-
cpe:2.3:o:redhat:enterprise_linux:7.0