Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3rw-wcj6-8cjf

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.2

Описание

OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

Пакеты

Наименование

cinder

pip
Затронутые версииВерсия исправления

< 7.0.0a0

7.0.0a0

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 12 лет назад

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

redhat
больше 12 лет назад

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

nvd
больше 12 лет назад

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

debian
больше 12 лет назад

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinde ...

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-200