Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ironic Unredacted Credentials via Volume Properties PATCH | openstack ironic: OpenStack Ironic: Information disclosure via PATCH request on volume properties |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 16 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. | In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. |
| References |
|
Mon, 15 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ironic Unredacted Credentials via Volume Properties PATCH |
Sun, 14 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-212 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T22:38:18.549Z
Reserved: 2026-06-14T03:49:37.600Z
Link: CVE-2026-54421
Updated: 2026-06-16T22:38:18.549Z
Status : Deferred
Published: 2026-06-14T04:16:30.927
Modified: 2026-06-16T15:51:29.037
Link: CVE-2026-54421
OpenCVE Enrichment
Updated: 2026-06-17T22:15:02Z