CVE-2024-32498
05.07.2024, 02:15
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openstack | cinder | 𝑥 < 22.1.3 |
| openstack | cinder | 23.0.0 ≤ 𝑥 < 23.1.1 |
| openstack | cinder | 24.0.0 |
| openstack | glance | 𝑥 < 26.0.1 |
| openstack | glance | 28.0.0 ≤ 𝑥 < 28.0.2 |
| openstack | glance | 27.0.0 |
| openstack | nova | 𝑥 < 27.3.1 |
| openstack | nova | 28.0.0 ≤ 𝑥 < 28.1.1 |
| openstack | nova | 29.0.0 ≤ 𝑥 < 29.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cinder |
| ||||||||||||||
| glance |
| ||||||||||||||
| nova |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cinder |
| ||||||||||||||||||
| glance |
| ||||||||||||||||||
| nova |
|
Common Weakness Enumeration
References