Impact
OpenStack Ironic versions up to 38.0.0 can transmit HTTP when the Image Service is configured to use these credentials. This flaw exposes the username and password to anyone who can observe the traffic to that host, potentially allowing attackers to gain unauthorized access to the image registry or other services protected by those credentials. The vulnerability impacts confidentiality by risking credential disclosure but does not enable remote code execution or direct system compromise.
Affected Systems
The affected product is OpenStack Ironic, all releases through version 38.0.0. The issue is present in any deployment that configures the Image Service to use HTTP or HTTPS Basic Authentication, regardless of other components.
Risk and Exploitability
The CVSS score of 6.3 categorizes this as a moderate-severity issue. The EPSS score is < 1%, and the CVE is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at present. The likely attack vector is that an attacker controls or compromises the unexpected remote host and receives the transmitted credentials. Exploitation requires the configuration of the Image Service to use Basic Authentication and the presence of a remote host to capture the credentials; no elevation of privileges or code execution is involved. The risk is primarily in credential exposure and subsequent lateral movement or service compromise by the attacker.
OpenCVE Enrichment