Lucene search

K
githubGitHub Advisory DatabaseGHSA-QHCH-G8QR-P497
HistoryMay 17, 2022 - 4:21 a.m.

OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability

2022-05-1704:21:11
CWE-200
GitHub Advisory Database
github.com
16

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.2%

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.

Affected configurations

Vulners
Node
openstackcinderRange<2014.1.3
CPENameOperatorVersion
cinderlt2014.1.3

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.2%