Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15139

Опубликовано: 27 авг. 2018
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cinderfixed2:13.0.0-1experimentalpackage
cinderfixed2:13.0.0-2package
cinderno-dsastretchpackage
cindernot-affectedjessiepackage

Примечания

  • https://wiki.openstack.org/wiki/OSSN/OSSN-0084

  • https://bugs.launchpad.net/ossn/+bug/1699573

EPSS

Процентиль: 47%
0.00242
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

CVSS3: 4.8
redhat
больше 7 лет назад

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

CVSS3: 7.5
nvd
больше 7 лет назад

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

EPSS

Процентиль: 47%
0.00242
Низкий