Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-17376

Опубликовано: 26 авг. 2020
Источник: ubuntu
Приоритет: low
CVSS2: 6.5
CVSS3: 8.3

Описание

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.

РелизСтатусПримечание
bionic

released

2:17.0.13-0ubuntu5.3
devel

not-affected

3:23.0.0-0ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

not-affected

libvirt is earlier than 1.3.4
esm-infra/bionic

released

2:17.0.13-0ubuntu5.3
esm-infra/focal

released

2:21.2.4-0ubuntu2.1
esm-infra/xenial

not-affected

libvirt is earlier than 1.3.4
focal

released

2:21.2.4-0ubuntu2.1
groovy

ignored

end of life
hirsute

not-affected

3:23.0.0-0ubuntu1

Показывать по

6.5 Medium

CVSS2

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
redhat
около 6 лет назад

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.

CVSS3: 8.3
nvd
около 6 лет назад

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.

CVSS3: 8.3
debian
около 6 лет назад

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in O ...

CVSS3: 8.3
github
больше 4 лет назад

OpenStack Nova Live migration fails to update persistent domain XML

6.5 Medium

CVSS2

8.3 High

CVSS3