A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NRed Hat Openstack
APPRedhatall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2015-5741CRITICAL9.8PL ✓same product
HTTP Request Smuggling w bibliotece net/http języka Go
CVE-2019-14859CRITICAL9.1PL ✓same product
Błędna weryfikacja podpisów DER w bibliotece python-ecdsa
CVE-2013-2167CRITICAL9.8PL ✓same product
Pominięcie podpisu middleware memcache w python-keystoneclient
CVE-2013-2166CRITICAL9.8PL ✓same product
Obejście szyfrowania middleware memcache w python-keystoneclient
CVE-2018-17963CRITICAL9.8PL ✓same product
QEMU: przepełnienie liczby całkowitej w obsłudze pakietów sieciowych (CWE-190)