CVE-2015-1851
published 2015-06-25CVE-2015-1851: OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read…
PriorityP433medium6.8CVSS 2.0
AVNACLAuSCCINAN
EPSS
2.62%
83.8th percentile
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | cinder | < cinder 2015.1.0+2015.06.16.git26.9634b76ba5-1 (bookworm) | cinder 2015.1.0+2015.06.16.git26.9634b76ba5-1 (bookworm) |
| openstack | cinder | >= 0 < 2015.1.0+2015.06.16.git26.9634b76ba5-1 | 2015.1.0+2015.06.16.git26.9634b76ba5-1 |
| openstack | cinder | >= 0 < 2015.1.0+2015.06.16.git26.9634b76ba5-1 | 2015.1.0+2015.06.16.git26.9634b76ba5-1 |
| openstack | cinder | >= 0 < 2015.1.0+2015.06.16.git26.9634b76ba5-1 | 2015.1.0+2015.06.16.git26.9634b76ba5-1 |
| openstack | cinder | >= 0 < 2015.1.0+2015.06.16.git26.9634b76ba5-1 | 2015.1.0+2015.06.16.git26.9634b76ba5-1 |
| openstack | cinder | >= 0 < 7.0.0a0 | 7.0.0a0 |
| openstack | icehouse | <= 2014.1.4 | — |
| openstack | juno | — | — |
| openstack | juno | — | — |
| openstack | juno | — | — |
| openstack | kilo | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Cinder vulnerability
vendor_ubuntu·2015-08-06
CVE-2015-1851 Cinder vulnerability
Title: Cinder vulnerability
Summary: Cinder could be made to access unintended files over the network by an
authenticated user.
Bastian Blank discovered that Cinder guessed image formats based on
untrusted data. An attacker could use this to read arbitrary files from
the Cinder host.
Instructions: After a standard system update you need to restart cinder to make all the
necessary changes.
Red Hat
openstack-cinder: Host file disclosure through qcow2 backing file
vendor_redhat·2015-06-12·CVSS 6.8
CVE-2015-1851 [MEDIUM] openstack-cinder: Host file disclosure through qcow2 backing file
openstack-cinder: Host file disclosure through qcow2 backing file
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
A flaw was found in the OpenStack Block Storage (cinder) upload-to-image functionality. When processing a malicious qcow2 header, cinder could be tricked into reading an arbitrary file from the cinder host.
Package: openstack-cinder (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Debian
CVE-2015-1851: cinder - OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), an...
vendor_debian·2015·CVSS 6.8
CVE-2015-1851 [MEDIUM] CVE-2015-1851: cinder - OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), an...
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Scope: local
bookworm: resolved (fixed in 2015.1.0+2015.06.16.git26.9634b76ba5-1)
bullseye: resolved (fixed in 2015.1.0+2015.06.16.git26.9634b76ba5-1)
forky: resolved (fixed in 2015.1.0+2015.06.16.git26.9634b76ba5-1)
sid: resolved (fixed in 2015.1.0+2015.06.16.git26.9634b76ba5-1)
trixie: resolved (fixed in 2015.1.0+2015.06.16.git26.9634b76ba5-1)
GHSA
OpenStack Cinder file disclosure in image convert
ghsa·2022-05-17
CVE-2015-1851 [MEDIUM] CWE-200 OpenStack Cinder file disclosure in image convert
OpenStack Cinder file disclosure in image convert
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
OSV
OpenStack Cinder file disclosure in image convert
osv·2022-05-17
CVE-2015-1851 [MEDIUM] OpenStack Cinder file disclosure in image convert
OpenStack Cinder file disclosure in image convert
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
OSV
CVE-2015-1851: OpenStack Cinder before 2014
osv·2015-06-25·CVSS 6.8
CVE-2015-1851 [MEDIUM] CVE-2015-1851: OpenStack Cinder before 2014
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file
bugzilla·2015-06-15·CVSS 6.8
CVE-2015-1851 [MEDIUM] CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file
CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file
Title: Host file disclosure through qcow2 backing file
Reporter: Bastian Blank (credativ)
Products: Cinder and Nova
Affects: up to 2014.1.4 and 2014.2 versions through 2014.2.2
Description:
Bastian Blank from credativ reported a vulnerability in Cinder and Nova.
By overwriting an image with a malicious qcow2 header, an authenticated
user may mislead Cinder upload-to-image action, resulting in disclosure
of any file from the Cinder server. A similar vulnerability in Nova can
also be used by an authenticated user to trick Nova during a snapshot
upload, resulting in disclosure of any file for which the Nova process
user has access to. All Cinder and Nova setups are affected.
Upstream bug: https://bugs.launchpad
Bugzilla
CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file [fedora-all]
bugzilla·2015-06-15·CVSS 6.8
CVE-2015-1851 [MEDIUM] CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file [fedora-all]
CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1206.htmlhttp://www.debian.org/security/2015/dsa-3292http://www.openwall.com/lists/oss-security/2015/06/13/1http://www.openwall.com/lists/oss-security/2015/06/17/2http://www.openwall.com/lists/oss-security/2015/06/17/7http://www.ubuntu.com/usn/USN-2703-1https://bugs.launchpad.net/cinder/+bug/1415087http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1206.htmlhttp://www.debian.org/security/2015/dsa-3292http://www.openwall.com/lists/oss-security/2015/06/13/1http://www.openwall.com/lists/oss-security/2015/06/17/2http://www.openwall.com/lists/oss-security/2015/06/17/7http://www.ubuntu.com/usn/USN-2703-1https://bugs.launchpad.net/cinder/+bug/1415087
2015-06-25
Published