Warn about CVE-2024-44082

Unmaintained Ironic-Python-Agent branches will not be patched against
CVE-2024-44082. This patch updates the release notes and readme
instructing deployers how to mitigate their risk using the provided
Ironic conductor patches.

Related-Bug: 2071740
Change-Id: Ie4aeef4af01ead5c18b359a22ab488de0c35248a
This commit is contained in:
Jay Faulkner 2024-08-20 15:09:33 -07:00
parent f2712779aa
commit a1b9170520
2 changed files with 16 additions and 0 deletions

@ -11,6 +11,11 @@ Team and repository tags
Overview
========
*WARNING:* The Ironic-Python-Agent version in this branch is vulnerable to
CVE-2024-44082. Do not run this in production unless using a patched
conductor with ``[conductor]/conductor_always_validate_images`` set to
``True``.
An agent for controlling and deploying Ironic controlled baremetal nodes.
The ironic-python-agent works with the agent driver in Ironic to provision

@ -0,0 +1,11 @@
---
security:
- |
Ironic-Python-Agent versions prior to the 2023.1 release are vulnerable to
CVE-2024-44082, tracked in
`bug 2071740 <https://bugs.launchpad.net/bugs/2071740>_`. Deployers of
Ironic versions Zed or older must apply CVE-2024-44082 fixes to their
Ironic environment and leave (default for all releases Zed and older)
``[conductor]/conductor_always_validates_images`` set to ``True``. This
ensures the conductor will security check the image because
Ironic-Python-Agent will not.