pypi package report

Is ironic safe?

9 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
2.9%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-f7cr-7c2c-fm8r, the advisory selected below

// advisories

GHSA-f7cr-7c2c-fm8r

HIGHCVE-2016-4985

The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVERNAME/vendorpassthru resource.

Affected
< 4.2.5, >= 5.0, < 5.1.2
Fixed in
4.2.5
Weakness
CWE-200
Published
2022-05-13
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 00:47 UTC. The most recent advisory here was published 2026-06-14. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is ironic safe? pypi package security report | CyberXYZ