First published: Thu May 11 2023(Updated: )
Jan Wasilewski and Gorka Eguileor discovered that os-brick incorrectly handled deleted volume attachments. An authenticated user or attacker could possibly use this issue to gain access to sensitive information. This update may require configuration changes to be completely effective, please see the upstream advisory for more information: https://security.openstack.org/ossa/OSSA-2023-003.html
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-os-brick | <6.2.0-0ubuntu2.1 | 6.2.0-0ubuntu2.1 |
=23.04 | ||
All of | ||
ubuntu/python3-os-brick | <6.1.0-0ubuntu1.1 | 6.1.0-0ubuntu1.1 |
=22.10 | ||
All of | ||
ubuntu/python3-os-brick | <5.2.2-0ubuntu1 | 5.2.2-0ubuntu1 |
=22.04 | ||
All of | ||
ubuntu/python3-os-brick | <3.0.8-0ubuntu1.1 | 3.0.8-0ubuntu1.1 |
=20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this os-brick vulnerability is USN-6073-4.
The os-brick vulnerability could allow an authenticated user or attacker to gain access to sensitive information.
An attacker can exploit this os-brick vulnerability by exploiting the incorrectly handled deleted volume attachments.
The versions of Ubuntu affected by this os-brick vulnerability are 23.04, 22.10, and 22.04.
To fix this os-brick vulnerability, update the python3-os-brick package to version 6.2.0-0ubuntu2.1, 6.1.0-0ubuntu1.1, 5.2.2-0ubuntu1, or 3.0.8-0ubuntu1.1 depending on the Ubuntu version you are running.