Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm86-h44c-2r2m

Опубликовано: 24 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.5

Описание

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

Пакеты

Наименование

Nova

pip
Затронутые версииВерсия исправления

<= 27.4.0

Отсутствует

Наименование

Nova

pip
Затронутые версииВерсия исправления

>= 28.0.0, <= 28.2.0

Отсутствует

Наименование

Nova

pip
Затронутые версииВерсия исправления

>= 29.0.0, <= 29.1.0

Отсутствует

EPSS

Процентиль: 74%
0.00835
Низкий

5.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-436
CWE-552

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVSS3: 5.5
redhat
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVSS3: 6.5
nvd
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVSS3: 6.5
debian
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1. ...

EPSS

Процентиль: 74%
0.00835
Низкий

5.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-436
CWE-552