Description
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4978 | The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. |
Github GHSA |
GHSA-qhch-g8qr-p497 | OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability |
Ubuntu USN |
USN-2405-1 | OpenStack Cinder vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:50:17.930Z
Reserved: 2014-05-14T00:00:00.000Z
Link: CVE-2014-3641
No data.
Status : Modified
Published: 2014-10-08T19:55:03.000
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-3641
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN