Fedora Account System
Red Hat Associate
Red Hat Customer
A vulnerability was found in Ironic Python Agent's bootc container deployment support. A malicious container can extract the secrets used to fetch from the OCI registry on deployment. Any Ironic user with the ability to deploy arbitrary containers from the bootc deploy_interface can exploit this. Affected versions: >=10.2.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1.