Executive brief
OpenStack Ironic is a service that manages bare-metal server provisioning and lifecycle in cloud environments. When users with limited permissions send PATCH requests to update volume properties, the API returns sensitive iSCSI connection credentials (usernames, passwords) in the response that should have been redacted. An attacker with volume update permissions but without credential-viewing permissions can exploit this to obtain storage credentials and connect to volumes outside the normal provisioning workflow, bypassing access controls.
Technical details
The vulnerability is an improper removal of sensitive information before transfer (CWE-212) in OpenStack Ironic's volume target API. The root cause is that the `baremetal:volume:view_target_properties` RBAC policy is enforced on GET endpoints but was missing from PATCH and POST write methods in `/v1/volume/targets`. When a PATCH request updates volume target fields, the API response includes the raw `properties` field containing iSCSI credentials without redaction. The attack requires a valid Keystone token with `baremetal:volume:update` or `baremetal:volume:create` permissions but without `view_target_properties` permission. No user interaction, network position beyond API access, or race conditions are needed. Impact is limited to multi-tenant deployments where these permission sets are separated; deployments granting both permissions together are unexploitable. Patches are available in multiple release branches (29.0.6, 32.0.2, 35.0.2, 37.0.1+).
Affected products
- OpenStack Ironic >=17.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1
Timeline
- 2026-06-14: disclosed: Vulnerability publicly disclosed in GitHub Advisory Database
- 2026-06-16: other: OpenStack Security Advisory OSSA-2026-023 issued
- 2026-06-03: patched: Patches merged for development and multiple release branches