Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-32498


An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.


Published

2024-07-05T02:15:09.840

Last Modified

2024-11-21T09:15:02.123

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-552

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack cinder < 22.1.3 Yes
Application openstack cinder < 23.1.1 Yes
Application openstack cinder 24.0.0 Yes
Application openstack glance < 26.0.1 Yes
Application openstack glance < 28.0.2 Yes
Application openstack glance 27.0.0 Yes
Application openstack nova < 27.3.1 Yes
Application openstack nova < 28.1.1 Yes
Application openstack nova < 29.0.3 Yes

References