PT-2018-5782 · Openstack · Openstack Cinder

Nick Tait

·

Published

2018-08-27

·

Updated

2023-02-03

·

CVE-2017-15139

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: openstack-cinder versions up to and including Queens
Description: A vulnerability was found in openstack-cinder, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
Recommendations: For openstack-cinder versions up to and including Queens, consider reconfiguring storage volume settings to avoid using thin volumes and zero padding with ScaleIO volumes until a fix is available. As a temporary workaround, restrict access to sensitive information stored on newly created volumes to minimize the risk of data leakage.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2017-15139
RHSA-2018:3601
RHSA-2019:0917
SUSE-SU-2019:0716-1

Affected Products

Openstack Cinder