CVE-2015-1851: Infoleak
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1851?
CVE-2015-1851 is classified as a moderately severe vulnerability that potentially allows unauthorized access to files on the server.
How do I fix CVE-2015-1851?
To fix CVE-2015-1851, upgrade to Cinder version 7.0.0a0 or later, or apply the appropriate patches for affected OpenStack versions.
Who is affected by CVE-2015-1851?
CVE-2015-1851 affects users of OpenStack Cinder versions prior to 2014.1.5, 2014.2.x before 2014.2.4, and 2015.1.x before 2015.1.1.
What exploitation method is used in CVE-2015-1851?
CVE-2015-1851 can be exploited by remote authenticated users using a crafted qcow2 signature in an image during the upload-to-image command.
What versions of OpenStack are impacted by CVE-2015-1851?
OpenStack versions Icehouse before 2014.1.5, Juno before 2014.2.4, and Kilo before 2015.1.1 are all impacted by CVE-2015-1851.