VulnerabilityModified
CVE-2015-1851
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
MEDIUM 6.8EPSS 2.64%
Does this matter?
Lower severity and a low EPSS score (2.64%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- canonical/ubuntu linux · openstack/icehouse · openstack/juno · openstack/kilo
- Source
- secalert@redhat.com
References
- http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1206.html
- http://www.debian.org/security/2015/dsa-3292
- http://www.openwall.com/lists/oss-security/2015/06/13/1
- http://www.openwall.com/lists/oss-security/2015/06/17/2
- http://www.openwall.com/lists/oss-security/2015/06/17/7
- http://www.ubuntu.com/usn/USN-2703-1
- https://bugs.launchpad.net/cinder/+bug/1415087
- http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1206.html
- http://www.debian.org/security/2015/dsa-3292
- http://www.openwall.com/lists/oss-security/2015/06/13/1
- http://www.openwall.com/lists/oss-security/2015/06/17/2
- http://www.openwall.com/lists/oss-security/2015/06/17/7
- http://www.ubuntu.com/usn/USN-2703-1
- https://bugs.launchpad.net/cinder/+bug/1415087
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.