{"id":"UBUNTU-CVE-2016-4985","details":"The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.","modified":"2025-07-16T07:34:37.251659Z","published":"2016-07-12T19:59:00Z","upstream":["CVE-2016-4985"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-4985"},{"type":"REPORT","url":"https://marc.info/?l=oss-security&m=146654947532322&w=2"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2016-4985"}],"affected":[{"package":{"name":"ironic","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ironic@1:5.1.2-0ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:5.1.2-0ubuntu1"}]}],"versions":["1:4.2.0-0ubuntu1","1:4.3.0-0ubuntu1","1:5.1.0-0ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ironic-api","binary_version":"1:5.1.2-0ubuntu1"},{"binary_name":"ironic-common","binary_version":"1:5.1.2-0ubuntu1"},{"binary_name":"ironic-conductor","binary_version":"1:5.1.2-0ubuntu1"},{"binary_name":"python-ironic","binary_version":"1:5.1.2-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-4985.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}