File Write Vulnerability in OpenStack Ironic by OpenStack
CVE-2025-44021
What is CVE-2025-44021?
OpenStack Ironic, prior to version 29.0.1, contains a vulnerability that allows unintended file writing to target node disks during image handling. When deployments are executed via the API, a malicious actor can provide a file path, potentially leading to the corruption or unauthorized alteration of Node disk data. While exploitation requires certain conditions, such as insecure configurations or disabled automated cleaning, it poses a real threat in environments lacking default security measures. Updated versions (24.1.3, 26.1.1, and 29.0.1) effectively mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ironic 24 < 24.1.3
Ironic 25 < 26.1.1
Ironic 27 < 29.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
