-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ironic | pip | >= 25.0.0, < 26.1.1 | 26.1.1 |
| ironic | pip | >= 23.1.0, < 24.1.3 | 24.1.3 |
| ironic | pip | >= 22.0.0, < 23.0.3 | 23.0.3 |
| ironic | pip | <= 21.4.3 |
The vulnerability stems from missing checksum validation when converting downloaded images to raw format. Key indicators are: