Safety vulnerability ID: 58699
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Kolla-ansible 16.0.0.0rc1 includes a fix for CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
https://opendev.org/openstack/kolla-ansible/commit/a77ea13ef1991543df29b7eea14b1f91ef26f858
Latest version: 19.1.0
Ansible Deployment of Kolla containers
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality. See CVE-2023-2088.
MISC:https://bugs.launchpad.net/bugs/2004555: https://bugs.launchpad.net/bugs/2004555
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application