Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvf4-jv3j-73mq

Опубликовано: 12 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

EPSS

Процентиль: 44%
0.00212
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-440

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 9.1
redhat
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 6.5
nvd
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

CVSS3: 6.5
debian
больше 2 лет назад

A flaw was found in OpenStack due to an inconsistency between Cinder a ...

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость платформы облачных сервисов Openstack, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 44%
0.00212
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-440