Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7548

Опубликовано: 07 янв. 2016
Источник: redhat
CVSS2: 6.3
EPSS Низкий

Описание

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

A flaw was discovered in the OpenStack Compute (nova) snapshot feature when using the libvirt driver. A compute user could overwrite an attached instance disk with a malicious header specifying a backing file, and then request a snapshot, causing a file from the compute host to be leaked. This flaw only affects LVM or Ceph setups, or setups using filesystem storage with "use_cow_images = False".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 8 (Liberty)openstack-novaNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-novaFixedRHSA-2016:001710.01.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-novaFixedRHSA-2016:001811.01.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-novaFixedRHSA-2016:001811.01.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7openstack-novaFixedRHSA-2016:001811.01.2016

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1290511openstack-nova: Unprivileged API user can access host data using instance snapshot

EPSS

Процентиль: 39%
0.00172
Низкий

6.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 3.5
ubuntu
около 10 лет назад

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

CVSS3: 3.5
nvd
около 10 лет назад

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

CVSS3: 3.5
debian
около 10 лет назад

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0 ...

CVSS3: 3.5
github
больше 3 лет назад

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

EPSS

Процентиль: 39%
0.00172
Низкий

6.3 Medium

CVSS2