{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T07:16:33.840","vulnerabilities":[{"cve":{"id":"CVE-2024-44082","sourceIdentifier":"cve@mitre.org","published":"2024-09-06T01:15:11.150","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed version details are: Ironic: <21.4.3, >=22.0.0 <23.0.2, >=23.1.0 <24.1.2, >=25.0.0 <26.0.1; Ironic-python-agent: <9.4.2, >=9.5.0 <9.7.1, >=9.8.0 <9.11.1, >=9.12.0 <9.13.1."},{"lang":"es","value":"En OpenStack Ironic anterior a la versión 26.0.1 y en ironic-python-agent anterior a la versión 9.13.1, existe una vulnerabilidad en el procesamiento de imágenes, en la que un usuario autenticado podría utilizar una imagen creada para explotar comportamientos no deseados en qemu-img, incluido un posible acceso no autorizado a datos potencialmente confidenciales. Los detalles de la versión afectada/corregida son: Ironic: &lt;21.4.3, &gt;=22.0.0 &lt;23.0.2, &gt;=23.1.0 &lt;24.1.2, &gt;=25.0.0 &lt;26.0.1; Ironic-python-agent: &lt;9.4.2, &gt;=9.5.0 &lt;9.7.1, &gt;=9.8.0 &lt;9.11.1, &gt;=9.12.0 &lt;9.13.1."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://bugs.launchpad.net/ironic/+bug/2071740","source":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2024-003.html","source":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2024/09/04/4","source":"cve@mitre.org"}]}}]}