First published: Wed Jul 10 2024(Updated: )
Arnaud Morin (OVH) reported a vulnerability in Nova. By supplying a raw format image which is actually a specially crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file’s contents from the server resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Nova | >=29.0.0<=29.1.0 | |
pip/Nova | >=28.0.0<=28.2.0 | |
pip/Nova | <=27.4.0 | |
debian/nova | 2:22.0.1-2+deb11u1 2:22.4.0-1~deb11u5 2:26.2.2-1~deb12u3 2:29.0.2-4 | |
OpenStack Nova | <27.4.1 | |
OpenStack Nova | >=28.0.0<28.2.1 | |
OpenStack Nova | >=29.0.0<29.1.1 | |
<27.4.1 | ||
>=28.0.0<28.2.1 | ||
>=29.0.0<29.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.