Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwhr-h69g-8qmq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Nova Information leak in libvirt LVM-backed instances

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 12.0.0a0

12.0.0a0

EPSS

Процентиль: 77%
0.01057
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

redhat
около 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

nvd
около 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

debian
около 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when usin ...

EPSS

Процентиль: 77%
0.01057
Низкий

Дефекты

CWE-200