OSSN-0110: Ironic can leak basic auth credentials to image server (2026-10-08)

Summary

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io security team reported a vulnerability in Ironic. When [deploy]/image_server_auth_strategy option is configured for HTTP(S) Basic Authentication, the operator’s image server username and password are sent to every host from which image data is requested. Any tenant with access to perform a deployment can set instance_info/image_source or instance_info/image_checksum to a host they control, triggering this vulnerability.

Affected Services / Software

  • ironic (‘>=24.0.0 <29.1.1, >=30.0.0 <32.1.1, >=33.0.0 <35.1.1, >=36.0.0 <39.0.0’)

Discussion

The fix adds a [deploy]/image_server_auth_hosts option allowing operators to restrict the hosts to which credentials are sent, along with a [deploy]/image_server_auth_permit_unknown_hosts option.

Deployments of OpenStack-integrated Ironic typically use Glance for image management and are not impacted by this vulnerability.

Contacts / References

Author: Jay Faulkner (G-Research OSS)