First published: Thu Jun 25 2015(Updated: )
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =15.04 | |
Openstack Icehouse | <=2014.1.4 | |
Openstack Juno | =2014.2 | |
Openstack Juno | =2014.2.2 | |
Openstack Juno | =2014.2.3 | |
Openstack Kilo | =2015.1.0 | |
pip/cinder | <7.0.0a0 | 7.0.0a0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.