In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
{
"cwe_ids": [
"CWE-212"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-25T16:34:55Z",
"nvd_published_at": "2026-06-14T04:16:30Z",
"severity": "MODERATE"
}