Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40767

Опубликовано: 23 июл. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

An arbitrary file access flaw was found in Nova. By supplying a RAW format image, a specially crafted QCOW2 image with a backing file path, or a VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file’s contents from the server. This issue results in unauthorized access to potentially sensitive data.

Отчет

This vulnerability was rated with a severity of Important due to the potential to read sensitive information from a Nova compute host. This vulnerability was introduced as a result of the fixes for CVE-2024-32498 and only affects versions of Nova that include the patches for CVE-2024-32498.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 18.0openstack-novaNot affected
Red Hat OpenStack Platform 16.1openstack-novaFixedRHSA-2024:511308.08.2024
Red Hat OpenStack Platform 16.2openstack-novaFixedRHSA-2024:509707.08.2024
Red Hat OpenStack Platform 17.1 for RHEL 8openstack-novaFixedRHSA-2024:508207.08.2024
Red Hat OpenStack Platform 17.1 for RHEL 9openstack-novaFixedRHSA-2024:508307.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=2297217openstack-nova: Regression VMDK/qcow arbitrary file access

EPSS

Процентиль: 74%
0.00835
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVSS3: 6.5
nvd
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVSS3: 6.5
debian
больше 1 года назад

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1. ...

CVSS3: 6.5
github
больше 1 года назад

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

EPSS

Процентиль: 74%
0.00835
Низкий

5.5 Medium

CVSS3