OpenStack Ironic Python Agent 凭证提取漏洞 (CVE-2026-54422) 漏洞概述 OpenStack Ironic Python Agent (IPA) 在部署过程中存在安全漏洞。攻击者可以利用此漏洞,通过恶意容器提取用于从 OCI 注册表拉取镜像的机密信息(如凭证)。 影响范围 受影响组件: Ironic Python Agent 受影响版本: - >=10.2.0 =11.0.0 =11.3.0 <11.5.1 修复方案 1. 应用补丁: 操作员应应用提供的补丁。 2. 禁用接口: 或者,完全禁用 Ironic conductor 上的 boot deploy 接口。 补丁链接 https://review.opendev.org/998479 (2026.2/hibiscus (development)) https://review.opendev.org/998481 (2026.1/queensh) https://review.opendev.org/998484 (2025.2/tiamatgo) https://review.opendev.org/998486 (2025.1/queensy) https://review.opendev.org/998489 (bugfix/11.6) https://review.opendev.org/998491 (bugfix/11.4) https://review.opendev.org/998494 (bugfix/11.3) 参考链接 https://launchpad.net/bugs/2155826 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54422