Candidate: CVE-2016-4985 PublicDate: 2016-07-12 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4985 https://marc.info/?l=oss-security&m=146654947532322&w=2 Description: The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827886 Priority: medium Discovered-by: Devananda van der Veen Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_ironic: upstream_ironic: released (1:5.1.2-1) precise_ironic: DNE precise/esm_ironic: DNE trusty_ironic: not-affected (code not present) trusty/esm_ironic: DNE (trusty was not-affected [code not present]) vivid/stable-phone-overlay_ironic: DNE vivid/ubuntu-core_ironic: DNE wily_ironic: ignored (reached end-of-life) xenial_ironic: released (1:5.1.2-0ubuntu1) yakkety_ironic: ignored (reached end-of-life) zesty_ironic: ignored (reached end-of-life) artful_ironic: ignored (reached end-of-life) bionic_ironic: not-affected (1:5.1.2-1) cosmic_ironic: not-affected (1:5.1.2-1) devel_ironic: not-affected (1:5.1.2-1)