CVE-2022-47951 Information

Description

An issue was discovered in OpenStack Cinder before 19.1.2 20.x before 20.0.2 and 21.0.0; Glance before 23.0.1 24.x before 24.1.1 and 25.0.0; and Nova before 24.1.2 25.x before 25.0.2 and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path an authenticated user may convince systems to return a copy of that file’s contents from the server resulting in unauthorized access to potentially sensitive data.

Reference

https://security.openstack.org/ossa/OSSA-2023-002.html https://launchpad.net/bugs/1996188

Share on: