Impact
OpenStack Ironic before release 37.0.1 permits the creation or modification of nodes without checking that the node belongs to the same project as the user. This missing ownership validation can let an attacker add nodes to other, thereby gaining control over resources that should remain isolated to a different project. The vulnerability represents an Incorrect Authorization flaw (CWE-1220) and a Missing Authorization weakness (CWE-862). Based on the description, it is inferred that an attacker must have project‑manager or equivalent credentials to exploit the flaw, as only those users can initiate node‑creation or modification operations.
Affected Systems
Any OpenStack Ironic deployment running a version earlier than 37.0.1 is affected. No additional version ranges are explicitly stated in the advisory, so all older releases remain vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity. The EPSS score of < 1% denotes a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the attack vector is an authenticated user with project‑manager privileges. If exploited, the attacker could alter node ownership or state across project boundaries, potentially disrupting the target project's services.
OpenCVE Enrichment