Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2088

Опубликовано: 12 мая 2023
Источник: debian

Описание

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cinderfixed2:21.1.0-3package
cinderno-dsabusterpackage
python-glance-storefixed4.1.0-4package
python-glance-storeno-dsabullseyepackage
python-glance-storeno-dsabusterpackage
novafixed2:26.1.0-4package
novano-dsabullseyepackage
novano-dsabusterpackage
python-os-brickfixed4.1.0-3package
python-os-brickno-dsabullseyepackage
python-os-brickno-dsabusterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2023/05/10/5

  • https://bugs.launchpad.net/nova/+bug/2004555

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 9.1
redhat
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 6.5
nvd
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 6.5
github
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость платформы облачных сервисов Openstack, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию