Description
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3300-1 | glance security update |
Debian DLA |
DLA-3301-1 | cinder security update |
Debian DLA |
DLA-3302-1 | nova security update |
Debian DSA |
DSA-5336-1 | glance security update |
Debian DSA |
DSA-5337-1 | nova security update |
Debian DSA |
DSA-5338-1 | cinder security update |
EUVD |
EUVD-2023-0384 | OpenStack Cinder, glance, and Nova vulnerable to Path Traversal |
Github GHSA |
GHSA-7h75-hwxx-qpgc | OpenStack Cinder, glance, and Nova vulnerable to Path Traversal |
Ubuntu USN |
USN-5835-1 | Cinder vulnerability |
Ubuntu USN |
USN-5835-2 | OpenStack Glance vulnerability |
Ubuntu USN |
USN-5835-3 | Nova vulnerability |
Ubuntu USN |
USN-5835-4 | Cinder vulnerability |
Ubuntu USN |
USN-5835-5 | Nova vulnerability |
Ubuntu USN |
USN-6882-2 | Cinder regression |
References
History
Mon, 31 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-31T16:49:31.493Z
Reserved: 2022-12-24T00:00:00.000Z
Link: CVE-2022-47951
Updated: 2024-08-03T15:02:36.595Z
Status : Modified
Published: 2023-01-26T22:15:25.823
Modified: 2025-03-31T17:15:39.117
Link: CVE-2022-47951
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN