Lucene search

K
ubuntuUbuntuUSN-6882-1
HistoryJul 08, 2024 - 12:00 a.m.

Cinder vulnerability

2024-07-0800:00:00
ubuntu.com
17
cinder
ubuntu
qcow2
authenticated user
sensitive information

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

18.3%

Releases

  • Ubuntu 24.04 LTS
  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • cinder - OpenStack storage service

Details

Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.

OSVersionArchitecturePackageVersionFilename
Ubuntu24.04noarchpython3-cinder< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu24.04noarchcinder-api< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu24.04noarchcinder-backup< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu24.04noarchcinder-common< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu24.04noarchcinder-scheduler< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu24.04noarchcinder-volume< 2:24.0.0-0ubuntu1.2UNKNOWN
Ubuntu23.10noarchpython3-cinder< 2:23.0.0-0ubuntu1.4UNKNOWN
Ubuntu23.10noarchcinder-api< 2:23.0.0-0ubuntu1.4UNKNOWN
Ubuntu23.10noarchcinder-backup< 2:23.0.0-0ubuntu1.4UNKNOWN
Ubuntu23.10noarchcinder-common< 2:23.0.0-0ubuntu1.4UNKNOWN
Rows per page:
1-10 of 241

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

18.3%