CVE-2014-3641
published 2014-10-08CVE-2014-3641: The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume…
PriorityP419medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.86%
77.0th percentile
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2014.1.3-1 (bookworm) | cinder 2014.1.3-1 (bookworm) |
| openstack | cinder | <= 2014.1.2 | — |
| openstack | cinder | — | — |
| openstack | cinder | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | cinder | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | cinder | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | cinder | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | cinder | >= 0 < 2014.1.3 | 2014.1.3 |
| openstack | cinder | >= 0 < 1:2014.1.3-0ubuntu1.1 | 1:2014.1.3-0ubuntu1.1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
osv·2022-05-17
CVE-2014-3641 [MEDIUM] OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
GHSA
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
ghsa·2022-05-17
CVE-2014-3641 [MEDIUM] CWE-200 OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
OSV
cinder vulnerabilities
osv·2014-11-11·CVSS 4.0
CVE-2014-3641 [MEDIUM] cinder vulnerabilities
cinder vulnerabilities
Duncan Thomas discovered that OpenStack Cinder did not properly track the
file format when using the GlusterFS of Smbfs drivers. A remote
authenticated user could exploit this to potentially obtain file contents
from the compute host. (CVE-2014-3641)
Amrith Kumar discovered that OpenStack Cinder did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Cinder log files could obtain access to sensitive information.
(CVE-2014-7230)
OSV
CVE-2014-3641: The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014
osv·2014-10-08·CVSS 4.0
CVE-2014-3641 [MEDIUM] CVE-2014-3641: The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Ubuntu
OpenStack Cinder vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 4.0
CVE-2014-3641 [MEDIUM] OpenStack Cinder vulnerabilities
Title: OpenStack Cinder vulnerabilities
Summary: OpenStack Cinder could be made to expose sensitive information over the
network.
Duncan Thomas discovered that OpenStack Cinder did not properly track the
file format when using the GlusterFS of Smbfs drivers. A remote
authenticated user could exploit this to potentially obtain file contents
from the compute host. (CVE-2014-3641)
Amrith Kumar discovered that OpenStack Cinder did not properly sanitize log
message contents. Under certain circumstances, a local attacker with read
access to Cinder log files could obtain access to sensitive information.
(CVE-2014-7230)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-cinder: Cinder-volume host data leak to virtual machine instance
vendor_redhat·2014-10-02·CVSS 4.0
CVE-2014-3641 [MEDIUM] CWE-22 openstack-cinder: Cinder-volume host data leak to virtual machine instance
openstack-cinder: Cinder-volume host data leak to virtual machine instance
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Package: openstack-cinder (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2014-3641: cinder - The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1....
vendor_debian·2014·CVSS 4.0
CVE-2014-3641 [MEDIUM] CVE-2014-3641: cinder - The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1....
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
forky: resolved (fixed in 2014.1.3-1)
sid: resolved (fixed in 2014.1.3-1)
trixie: resolved (fixed in 2014.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance [fedora-all]
bugzilla·2014-10-03·CVSS 4.0
CVE-2014-3641 [MEDIUM] CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance [fedora-all]
CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance
bugzilla·2014-09-16·CVSS 4.0
CVE-2014-3641 [MEDIUM] CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance
CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance
The OpenStack project reports:
""
Title: Cinder-volume host data leak to vm instance
Reporter: Duncan Thomas (HP)
Products: Cinder
Versions: up to 2014.1.2
Description:
Duncan Thomas from Hewlett Packard reported a vulnerability in Cinder
GlusterFS and Linux Smbfs driver. By overwriting a volume from within an
instance with a malicious qcow2 header, an authenticated user may be
able to clone and attach that corrupted volume resulting in affected
drivers leaking an arbitrary file from the Cinder-volume host to the
virtual instance. Note that the host file must be readable by the Cinder
context to be exposed. Only Cinder setups using GlusterFS volume driver
configured with glusterfs_qcow2_volumes=Fals
http://rhn.redhat.com/errata/RHSA-2014-1787.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1788.htmlhttp://seclists.org/oss-sec/2014/q4/78http://www.securityfocus.com/bid/70221http://www.ubuntu.com/usn/USN-2405-1https://bugs.launchpad.net/cinder/+bug/1350504http://rhn.redhat.com/errata/RHSA-2014-1787.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1788.htmlhttp://seclists.org/oss-sec/2014/q4/78http://www.securityfocus.com/bid/70221http://www.ubuntu.com/usn/USN-2405-1https://bugs.launchpad.net/cinder/+bug/1350504
2014-10-08
Published