It was discovered that enabling debug mode in ironic-discoverd would also enable debug mode in flask, which would in turn enable the flask console on error. An attacker able to trigger an error and expose the flask console could use the console to run arbitary python code.
Created openstack-ironic-discoverd tracking bugs for this issue: Affects: fedora-all [bug 1273701]
This issue has been addressed in the following products: OpenStack 7.0 Director/Manager for RHEL 7 Via RHSA-2015:1929 https://access.redhat.com/errata/RHSA-2015:1929
openstack-ironic-discoverd-1.1.1-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
openstack-ironic-discoverd-1.1.1-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: OpenStack 6 for RHEL 7 Via RHSA-2015:2685 https://rhn.redhat.com/errata/RHSA-2015-2685.html