File tree Expand file tree Collapse file tree 2 files changed +16
-0
lines changed
Expand file tree Collapse file tree 2 files changed +16
-0
lines changed Original file line number Diff line number Diff line change @@ -11,6 +11,11 @@ Team and repository tags
1111Overview
1212========
1313
14+ *WARNING: * The Ironic-Python-Agent version in this branch is vulnerable to
15+ CVE-2024-44082. Do not run this in production unless using a patched
16+ conductor with ``[conductor]/conductor_always_validate_images `` set to
17+ ``True ``.
18+
1419An agent for controlling and deploying Ironic controlled baremetal nodes.
1520
1621The ironic-python-agent works with the agent driver in Ironic to provision
Original file line number Diff line number Diff line change 1+ ---
2+ security :
3+ - |
4+ Ironic-Python-Agent versions prior to the 2023.1 release are vulnerable to
5+ CVE-2024-44082, tracked in
6+ `bug 2071740 <https://bugs.launchpad.net/bugs/2071740>_`. Deployers of
7+ Ironic versions Zed or older must apply CVE-2024-44082 fixes to their
8+ Ironic environment and leave (default for all releases Zed and older)
9+ ``[conductor]/conductor_always_validates_images`` set to ``True``. This
10+ ensures the conductor will security check the image because
11+ Ironic-Python-Agent will not.
You can’t perform that action at this time.
0 commit comments