CVE-2015-7548

Severity
3.5LOW
EPSS
0.2%
top 61.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12
Latest updateMay 14

Description

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDopenstack/nova12.0.012.0.1+1
Debiannova< 2:13.0.0~rc3-1+3

🔴Vulnerability Details

3
GHSA
GHSA-6q7v-7634-xrvf: OpenStack Compute (Nova) before 20152022-05-14
OSV
CVE-2015-7548: OpenStack Compute (Nova) before 20152016-01-12
CVEList
CVE-2015-7548: OpenStack Compute (Nova) before 20152016-01-12

📋Vendor Advisories

3
Ubuntu
OpenStack Nova vulnerabilities2017-10-11
Red Hat
openstack-nova: Unprivileged API user can access host data using instance snapshot2016-01-07
Debian
CVE-2015-7548: nova - OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (libert...2015

💬Community

2
Bugzilla
CVE-2015-7548 openstack-nova: Unprivileged API user can access host data using instance snapshot [fedora-all]2016-01-07
Bugzilla
CVE-2015-7548 openstack-nova: Unprivileged API user can access host data using instance snapshot2015-12-10
CVE-2015-7548 (LOW CVSS 3.5) | OpenStack Compute (Nova) before 201 | cvebase.io