Safety vulnerability ID: 58700
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Cinder 22.1.0, 21.3.0 and 20.3.0 include a fix for CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
https://opendev.org/openstack/cinder/commit/68fdc323369943f494541a3510e71290b091359f
https://bugs.launchpad.net/nova/+bug/2004555
Latest version: 25.0.0
OpenStack Block Storage
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality. See CVE-2023-2088.
MISC:https://bugs.launchpad.net/bugs/2004555: https://bugs.launchpad.net/bugs/2004555
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application