← Vulnerability feed

Vulnerability record · CVE-2015-7514 · published 7 June 2017

CVE-2015-7514: Openstack ironic information exposure vulnerability

Openstack · Ironic

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

6.5 CVSS 3.0 Medium EPSS 1.6% · top 25.5% CWE-200 · Information exposure
6.5CVSS 3.0 base score, v2 4.0
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2015/12/03/4 Mailing ListVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1285809 Issue TrackingPatchThird Party AdvisoryVDB Entry
https://review.openstack.org/#/c/252993 Issue TrackingPatchVendor Advisory
https://review.openstack.org/#/c/253001 Issue TrackingPatchVendor Advisory
http://www.openwall.com/lists/oss-security/2015/12/03/4 Mailing ListVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1285809 Issue TrackingPatchThird Party AdvisoryVDB Entry
https://review.openstack.org/#/c/252993 Issue TrackingPatchVendor Advisory
https://review.openstack.org/#/c/253001 Issue TrackingPatchVendor Advisory

Track CVE-2015-7514 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-48681Openstack ironic relative path traversal vulnerabilityOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.85%7.7CVE-2026-46447Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.EPSS 0.43%7.7CVE-2026-42997Openstack ironic vulnerabilityAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a re…EPSS 0.54%7.5CVE-2026-50589Openstack ironic allocation without limits vulnerabilityIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…EPSS 0.74%7.2CVE-2026-42510Openstack ironic inclusion from untrusted sphere vulnerabilityOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.74%6.5CVE-2026-44919Openstack ironic vulnerabilityIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero …EPSS 0.56%4.9CVE-2026-44917Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_templa…EPSS 0.47%3.0CVE-2026-44916Openstack ironic vulnerabilityIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2015-7514), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.