VDB
KO
MEDIUM

GHSA-qhch-g8qr-p497

OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Details

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / cinder
Introduced in: 0 Fixed in: 2014.1.3
Fix pip install --upgrade 'cinder>=2014.1.3'

References