First published: Tue Jan 12 2016(Updated: )
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | >=12.0.0<12.0.1 | |
OpenStack Nova | >=2015.1.0<2015.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7548 is considered a critical vulnerability due to its ability to allow remote authenticated users to read arbitrary files.
To fix CVE-2015-7548, upgrade OpenStack Nova to version 2015.1.3 or later for Kilo and 12.0.1 or later for Liberty.
CVE-2015-7548 affects OpenStack Nova versions before 2015.1.3 in Kilo and before 12.0.1 in Liberty.
The implications of CVE-2015-7548 include the potential exposure of sensitive data due to arbitrary file access by unauthorized users.
Organizations using vulnerable versions of OpenStack Nova with libvirt configured to use_cow_images set to false are at risk for CVE-2015-7548.