CVE-2024-32498
05.07.2024, 02:15
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | cinder | 𝑥 < 22.1.3 |
openstack | cinder | 23.0.0 ≤ 𝑥 < 23.1.1 |
openstack | cinder | 24.0.0 |
openstack | glance | 𝑥 < 26.0.1 |
openstack | glance | 28.0.0 ≤ 𝑥 < 28.0.2 |
openstack | glance | 27.0.0 |
openstack | nova | 𝑥 < 27.3.1 |
openstack | nova | 28.0.0 ≤ 𝑥 < 28.1.1 |
openstack | nova | 29.0.0 ≤ 𝑥 < 29.0.3 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cinder |
| ||||||||||||
glance |
| ||||||||||||
nova |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cinder |
| ||||||||||||||||
glance |
| ||||||||||||||||
nova |
|
Common Weakness Enumeration
References