Openstack

Cinder

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 05.07.2024 02:15:09
  • Zuletzt bearbeitet 04.11.2025 17:15:52

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 26.01.2023 22:15:25
  • Zuletzt bearbeitet 31.03.2025 17:15:39

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image ...

Exploit
  • EPSS 3.2%
  • Veröffentlicht 07.10.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk c...

  • EPSS 0.12%
  • Veröffentlicht 08.10.2014 19:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 08.10.2014 19:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by read...

  • EPSS 0.33%
  • Veröffentlicht 08.10.2014 19:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.

  • EPSS 0.16%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.

  • EPSS 0.84%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity...