CVE-2022-47951

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-47951
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47951.json
Aliases
Related
Published
2023-01-26T22:15:25Z
Modified
2023-11-29T10:01:31.085717Z
Details

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.

References

Affected packages

Git / github.com/openstack/cinder

Affected ranges

Type
GIT
Repo
https://github.com/openstack/cinder
Events
Type
GIT
Repo
https://github.com/openstack/glance
Events
Type
GIT
Repo
https://github.com/openstack/nova
Events
Type
GIT
Repo
https://opendev.org/openstack/cinder
Events
Introduced
c0ff6fd9f934782149777d2ab69b87dabca6a907

Affected versions

20.*

20.0.0
20.0.0.0rc2
20.0.1
20.1.0
20.2.0
20.3.0
20.3.1

24.*

24.0.0
24.0.0.0rc1
24.0.0.0rc2
24.1.0
24.2.0
24.2.1

25.*

25.0.0
25.0.0.0rc1
25.1.0

26.*

26.0.0
26.0.0.0b2
26.0.0.0b3
26.0.0.0rc1

27.*

27.0.0
27.0.0.0b1
27.0.0.0b2
27.0.0.0rc1

Other

ussuri-em