PT-2024-24616 · Openstack+2 · Openstack Glance+4

Martin Kaesberger

·

Published

2024-07-02

·

Updated

2026-04-22

·

CVE-2024-32498

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Cinder versions through 24.0.0 OpenStack Glance versions before 28.0.2 OpenStack Nova versions before 29.0.3
Description An issue was discovered in OpenStack, allowing arbitrary file access via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected. It is estimated that over 12,500 services are potentially affected.
Recommendations For OpenStack Cinder versions through 24.0.0, update to a version after 24.0.0 to resolve the issue. For OpenStack Glance versions before 28.0.2, update to version 28.0.2 or later to resolve the issue, but only if image conversion is enabled. For OpenStack Nova versions before 29.0.3, update to version 29.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to custom QCOW2 external data to minimize the risk of exploitation.

Fix

Information Disclosure

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-32498
DLA-3870-1
DLA-3871-1
DLA-3872-1
DLA-3873-1
DSA-5754-1
DSA-5755-1
DSA-5756-1
GHSA-R4V4-W9PV-6FPH
RHSA-2024:4272
RHSA-2024:4273
RHSA-2024:4274
RHSA-2024:4425
USN-6882-1
USN-6882-2
USN-6883-1
USN-6884-1
USN-8199-1

Affected Products

Linuxmint
Openstack Cinder
Openstack Glance
Openstack Nova
Ubuntu