Safety vulnerability ID: 72147
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A security flaw in affected versions of OpenStack Cinder allows arbitrary file access via custom QCOW2 external data. An authenticated user can supply a crafted QCOW2 image that references a specific data file path, convincing systems to return a copy of that file's contents from the server. This results in unauthorized access to potentially sensitive data.
Latest version: 25.0.0
OpenStack Block Storage
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application