Cinder

Latest version: v25.0.0

Vulnerabilities (12)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2023-2088 58700

Cinder 22.1.0, 21.3.0 and 20.3.0 include a fix for CVE-2023-2088: A f…

  • >=22.0.0.0rc1,<22.1.0
  • >=21.0.0.0rc2,<21.3.0
  • <20.3.0
MEDIUM 6.5
CVE-2022-47951 52929

Cinder 19.1.2, 20.0.2 and 21.0.0 include a fix for CVE-2022-47951: An…

  • <19.1.2
  • >=20.0.0.0rc1,<20.0.2
  • >=21.0.0.0rc1,<21.0.0
MEDIUM 5.7
CVE-2020-10755 38408

Cinder versions 14.1.0, 15.2.0 and 16.1.0 include a fix for CVE-2020-…

  • <14.1.0
  • >=15.0.0.0rc1,<15.2.0
  • >=16.0.0.0b1,<16.1.0
MEDIUM 6.5
CVE-2015-5162 35629

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; G…

  • <7.0.2
  • >=8.0.0,<8.1.1
HIGH 7.5
CVE-2014-7231 70430

The strutils.mask_password function in the OpenStack Oslo utility lib…

  • >=2013.2,<2013.2.4
  • >=2014.1,<2014.1.3
LOW 2.1
CVE-2014-7230 70424

The processutils.execute function in OpenStack oslo-incubator, Cinder…

  • >=2013.2,<2013.2.4
  • >=2014.1,<2014.1.3
LOW 2.1
CVE-2024-32498 72147

A security flaw in affected versions of OpenStack Cinder allows arbit…

  • <25.0.0.0rc1
MEDIUM 6.5
CVE-2013-4183 68017

The clear_volume function in LVMVolumeDriver driver in OpenStack Cind…

  • >=2012,<2013.1.3
LOW 2.1
CVE-2013-4202 68019

The (1) backup (api/contrib/backups.py) and (2) volume transfer (cont…

  • >=2012,<=2013.1.3
MEDIUM 4.3
CVE-2015-1851 70457

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4…

  • >2010,<2015.1.1
MEDIUM 6.8
CVE-2014-3641 35566

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder bef…

  • >=2010,<2014.1.3
MEDIUM 4.0
CVE-2013-1068 25651

The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2…

  • >=2000,<2013.2.3
MEDIUM 5.0