Description
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3292-1 | cinder security update |
EUVD |
EUVD-2022-3382 | OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command. |
Github GHSA |
GHSA-9hcj-h2qc-689p | OpenStack Cinder file disclosure in image convert |
Ubuntu USN |
USN-2703-1 | Cinder vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T04:54:16.372Z
Reserved: 2015-02-17T00:00:00.000Z
Link: CVE-2015-1851
No data.
Status : Modified
Published: 2015-06-25T16:59:00.077
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1851
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA
Ubuntu USN