CVE-2017-15139: Infoleak
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
Other sources
Summary Certain storage volume configurations allow newly created volumes to contain previous data. This could lead to leakage of sensitive information between tenants.
Affected Services / Software Cinder releases up to and including Queens with ScaleIO volumes using thin volumes and zero padding.
External references:
https://wiki.openstack.org/wiki/OSSN/OSSN-0084
Upstream bug:
https://bugs.launchpad.net/ossn/+bug/1699573
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-15139?
CVE-2017-15139 is a vulnerability found in openstack-cinder releases up to and including Queens.
How does CVE-2017-15139 affect the software?
CVE-2017-15139 allows newly created volumes in certain storage volume configurations to contain previous data, specifically affecting ScaleIO volumes using thin volumes and zero padding.
What is the severity of CVE-2017-15139?
CVE-2017-15139 has a severity rating of 7.5 (high).
How can I fix CVE-2017-15139?
To fix CVE-2017-15139, update to a version of openstack-cinder that is beyond the affected releases.
Where can I find more information about CVE-2017-15139?
You can find more information about CVE-2017-15139 at the following references: [1] [2] [3]