First published: Thu May 11 2023(Updated: )
Jan Wasilewski and Gorka Eguileor discovered that Cinder incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information. This update may require configuration changes to be completely effective, please see the upstream advisory for more information: https://security.openstack.org/ossa/OSSA-2023-003.html
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-cinder | <2:22.0.0-0ubuntu1.1 | 2:22.0.0-0ubuntu1.1 |
Ubuntu Ubuntu | =23.04 | |
All of | ||
ubuntu/python3-cinder | <2:21.1.0-0ubuntu2.1 | 2:21.1.0-0ubuntu2.1 |
Ubuntu Ubuntu | =22.10 | |
All of | ||
ubuntu/python3-cinder | <2:20.1.0-0ubuntu2.1 | 2:20.1.0-0ubuntu2.1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python3-cinder | <2:16.4.2-0ubuntu2.3 | 2:16.4.2-0ubuntu2.3 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security notice is USN-6073-1.
Jan Wasilewski and Gorka Eguileor discovered the vulnerability.
An authenticated user or attacker could gain access to sensitive information.
To fix this vulnerability, update the python3-cinder package to version 2:22.0.0-0ubuntu1.1 or later.
You can find more information about this vulnerability on the Ubuntu security website.