Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10789
HistoryJan 15, 2019 - 8:52 a.m.

Information Disclosure

2019-01-1508:52:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

49.6%

openstack-nova is vulnerable to information disclosure attacks. The vulnerability exists in the instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.