CVE-2024-32498: [OSSA-2024-001] OpenStack Cinder, Glance, Nova: Arbitrary file access through custom QCOW2 external data (CVE-2024-32498)
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32498?
CVE-2024-32498 is considered a medium severity vulnerability as it allows arbitrary file access through crafted QCOW2 images.
How do I fix CVE-2024-32498?
To fix CVE-2024-32498, upgrade to Cinder version 2:17.4.0 or later, Glance version 2:21.1.0 or later, or Nova version 2:22.4.0 or later.
Who is affected by CVE-2024-32498?
CVE-2024-32498 affects users of OpenStack Cinder versions up to 24.0.0, Glance up to 28.0.1, and Nova up to 29.0.2.
What types of systems are impacted by CVE-2024-32498?
CVE-2024-32498 impacts systems leveraging OpenStack cloud infrastructure components that allow for custom QCOW2 external data.
What exploitation method is used in CVE-2024-32498?
CVE-2024-32498 can be exploited by an authenticated user through a specially crafted QCOW2 image that references arbitrary file paths.