CVE-2017-15139
published 2018-08-27CVE-2017-15139: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.24%
66.1th percentile
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2:13.0.0-2 (bookworm) | cinder 2:13.0.0-2 (bookworm) |
| openstack | cinder | <= 12.0.4-7 | — |
| openstack | cinder | >= 0 < 2:13.0.0-2 | 2:13.0.0-2 |
| openstack | cinder | >= 0 < 2:13.0.0-2 | 2:13.0.0-2 |
| openstack | cinder | >= 0 < 2:13.0.0-2 | 2:13.0.0-2 |
| openstack | cinder | >= 0 < 2:13.0.0-2 | 2:13.0.0-2 |
| openstack_foundation | openstack-cinder | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-cinder: Data retained after deletion of a ScaleIO volume
vendor_redhat·2018-07-10·CVSS 7.5
CVE-2017-15139 [HIGH] CWE-200 openstack-cinder: Data retained after deletion of a ScaleIO volume
openstack-cinder: Data retained after deletion of a ScaleIO volume
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
An information-leak flaw was found in openstack-cinder deployments using the third-party EMC ScaleIO backend. It was possible for new volumes to contain previous data if they were created from storage pools which had disabled zero-padding. An attacker could exploit this flaw to obtain sensitive information.
Statement: With this update, disabled zero-padding is no longer the default for new volumes. U
Debian
CVE-2017-15139: cinder - A vulnerability was found in openstack-cinder releases up to and including Queen...
vendor_debian·2017·CVSS 7.5
CVE-2017-15139 [HIGH] CVE-2017-15139: cinder - A vulnerability was found in openstack-cinder releases up to and including Queen...
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
Scope: local
bookworm: resolved (fixed in 2:13.0.0-2)
bullseye: resolved (fixed in 2:13.0.0-2)
forky: resolved (fixed in 2:13.0.0-2)
sid: resolved (fixed in 2:13.0.0-2)
trixie: resolved (fixed in 2:13.0.0-2)
GHSA
GHSA-j9j4-4235-xf59: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurat
ghsa_unreviewed·2022-05-13
CVE-2017-15139 [HIGH] CWE-200 GHSA-j9j4-4235-xf59: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurat
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
OSV
CVE-2017-15139: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurat
osv·2018-08-27·CVSS 7.5
CVE-2017-15139 [HIGH] CVE-2017-15139: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurat
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume [openstack-rdo]
bugzilla·2018-07-31·CVSS 7.5
CVE-2017-15139 [HIGH] CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume [openstack-rdo]
CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
The current Scal
Bugzilla
CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume
bugzilla·2018-07-10·CVSS 7.5
CVE-2017-15139 [HIGH] CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume
CVE-2017-15139 openstack-cinder: Data retained after deletion of a ScaleIO volume
Summary
Certain storage volume configurations allow newly created volumes to contain previous data. This could lead to leakage of sensitive information between tenants.
Affected Services / Software
Cinder releases up to and including Queens with ScaleIO volumes using thin volumes and zero padding.
External references:
https://wiki.openstack.org/wiki/OSSN/OSSN-0084
Upstream bug:
https://bugs.launchpad.net/ossn/+bug/1699573
Discussion:
upstream fix:
https://git.openstack.org/cgit/openstack/cinder/commit/?id=5492e2206a7736079279f45e9c8b931ca19fb322
---
The 2018 upstream fix prevents the creation of thick volumes with disabled zero padding by default (although can be overridden with config option, sio_
https://access.redhat.com/errata/RHSA-2018:3601https://access.redhat.com/errata/RHSA-2019:0917https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15139https://wiki.openstack.org/wiki/OSSN/OSSN-0084https://access.redhat.com/errata/RHSA-2018:3601https://access.redhat.com/errata/RHSA-2019:0917https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15139https://wiki.openstack.org/wiki/OSSN/OSSN-0084
2018-08-27
Published