CVE-2025-44021 Details
Description
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the target node disk. This is difficult to exploit in practice, because a node deployed in this manner should never reach the ACTIVE state, but it still represents a danger in environments running with non-default, insecure configurations such as with automated cleaning disabled. The fixed versions are 24.1.3, 26.1.1, and 29.0.1.
A vulnerability in OpenStack Ironic versions prior to 29.0.1 allows for unintended file writes to a target node's disk during image processing, specifically when deployments are managed through the API. This issue arises because a malicious project, designated as the node owner, can specify a path to any local file accessible by ironic-conductor. While this vulnerability is challenging to exploit under normal circumstances—since a node should not enter the ACTIVE state if deployed in this way—it poses a risk in environments with non-default, insecure settings, such as those with automated cleaning turned off.
Users can upgrade to OpenStack Ironic versions 24.1.3, 26.1.1, or 29.0.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2025CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/05/08/1 | CVE | Mailing List |
| https://bugs.launchpad.net/ironic/+bug/2107847 | [email protected] | Issue TrackingVendor |
| https://security.openstack.org/ossa/OSSA-2025-001.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Ironic | < 24.1.3 (semver) < 26.1.1 (semver) < 29.0.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2025 | CVE Modified | CVE |
| May 8, 2025 | New CVE Received | [email protected] |
Volerion