PT-2023-1359 · Openstack+3 · Openstack Nova+5

Arnaud Morin

+3

·

Published

2023-01-24

·

Updated

2025-03-31

·

CVE-2022-47951

CVSS v2.0

6.6

Medium

VectorAV:N/AC:H/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Cinder versions prior to 19.1.2 OpenStack Cinder versions 20.x prior to 20.0.2 OpenStack Cinder version 21.0.0 OpenStack Glance versions prior to 23.0.1 OpenStack Glance versions 24.x prior to 24.1.1 OpenStack Glance version 25.0.0 OpenStack Nova versions prior to 24.1.2 OpenStack Nova versions 25.x prior to 25.0.2 OpenStack Nova version 26.0.0
Description The issue is related to the use of files and directories accessible to external parties in OpenStack Cinder. An authenticated user can exploit this by supplying a specially created VMDK flat image that references a specific backing file path, allowing them to convince systems to return a copy of that file's contents from the server. This results in unauthorized access to potentially sensitive data.
Recommendations For OpenStack Cinder versions prior to 19.1.2, update to version 19.1.2 or later. For OpenStack Cinder versions 20.x prior to 20.0.2, update to version 20.0.2 or later. For OpenStack Cinder version 21.0.0, update to a version later than 21.0.0. For OpenStack Glance versions prior to 23.0.1, update to version 23.0.1 or later. For OpenStack Glance versions 24.x prior to 24.1.1, update to version 24.1.1 or later. For OpenStack Glance version 25.0.0, update to a version later than 25.0.0. For OpenStack Nova versions prior to 24.1.2, update to version 24.1.2 or later. For OpenStack Nova versions 25.x prior to 25.0.2, update to version 25.0.2 or later. For OpenStack Nova version 26.0.0, update to a version later than 26.0.0. As a temporary workaround, consider restricting access to the VMDK image upload feature until a patch is available.

Exploit

Fix

Path traversal

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7960
ALT-PU-2024-1074
ALT-PU-2024-12521
ALT-PU-2024-3398
ALT-PU-2024-8418
ALT-PU-2024-9720
BDU:2023-00689
CVE-2022-47951
DLA-3300-1
DLA-3301-1
DLA-3302-1
DSA-5336-1
DSA-5337-1
DSA-5338-1
GHSA-7H75-HWXX-QPGC
RHSA-2023:1015
RHSA-2023:1016
RHSA-2023:1017
RHSA-2023:1278
RHSA-2023:1279
RHSA-2023:1280
SUSE-SU-2023:0844-1
SUSE-SU-2023:1949-1
USN-5835-1
USN-5835-2
USN-5835-3
USN-5835-4
USN-5835-5
USN-6882-2

Affected Products

Alt Linux
Linuxmint
Openstack Cinder
Openstack Glance
Openstack Nova
Ubuntu