OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
2015-06-25T16:59:00.077
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:L/Au:S/C:C/I:N/A:N
8.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Application | openstack | icehouse | ≤ 2014.1.4 | Yes |
Application | openstack | juno | 2014.2 | Yes |
Application | openstack | juno | 2014.2.2 | Yes |
Application | openstack | juno | 2014.2.3 | Yes |
Application | openstack | kilo | 2015.1.0 | Yes |