Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4v4-w9pv-6fph

Опубликовано: 05 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

Пакеты

Наименование

cinder

pip
Затронутые версииВерсия исправления

<= 24.0.0

Отсутствует

Наименование

glance

pip
Затронутые версииВерсия исправления

<= 28.0.1

Отсутствует

Наименование

nova

pip
Затронутые версииВерсия исправления

<= 29.0.2

Отсутствует

EPSS

Процентиль: 39%
0.00171
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-552

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

CVSS3: 8.8
redhat
больше 1 года назад

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

CVSS3: 6.5
nvd
больше 1 года назад

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

CVSS3: 6.5
debian
больше 1 года назад

An issue was discovered in OpenStack Cinder through 24.0.0, Glance bef ...

EPSS

Процентиль: 39%
0.00171
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-552