Safety vulnerability ID: 58668
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Nova 27.1.0, 26.2.0 and 25.2.0 include a fix for CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
https://opendev.org/openstack/nova/commit/db455548a12beac1153ce04eca5e728d7b773901
Latest version: 30.0.0
Cloud computing fabric controller
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality. See CVE-2023-2088.
MISC:https://bugs.launchpad.net/bugs/2004555: https://bugs.launchpad.net/bugs/2004555
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application