CVE-2024-31463 is a missing-authentication vulnerability in Metal3 ironic-image when reverse-proxy mode is enabled. With IRONIC_REVERSE_PROXY_SETUP enabled, HTTP Basic authentication is enforced by an HTTPD reverse-proxy container rather than by Ironic. Ironic also exposes its API through a private localhost listener by default. Processes that can reach that private listener bypass the reverse proxy and access the Ironic API without authentication. A similar condition affects Ironic Inspector when its reverse-proxy mode is enabled, though with lower attack potential. The issue is fixed in ironic-image 24.1.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated local-access vulnerability affecting the Ironic API in ironic-image.
An unauthenticated local-access vulnerability affecting the Ironic API in ironic-image.
An authentication-related flaw in the Ironic image that permits unauthenticated local access to the Ironic API.
An unauthenticated local-access vulnerability affecting the Ironic API component included in the OpenShift ironic-image.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.