CVE-2022-47951
published 2023-01-26CVE-2022-47951: An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova…
PriorityP431medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
1.03%
59.7th percentile
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2:21.0.0-3 (bookworm) | cinder 2:21.0.0-3 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | glance | < cinder 2:21.0.0-3 (bookworm) | cinder 2:21.0.0-3 (bookworm) |
| debian | nova | < cinder 2:21.0.0-3 (bookworm) | cinder 2:21.0.0-3 (bookworm) |
| debian | nova | — | — |
| glance_project | glance | >= 0 < 2:21.0.0-2+deb11u1 | 2:21.0.0-2+deb11u1 |
| glance_project | glance | >= 0 < 2:25.0.0-2 | 2:25.0.0-2 |
| glance_project | glance | >= 0 < 2:25.0.0-2 | 2:25.0.0-2 |
| glance_project | glance | >= 0 < 2:25.0.0-2 | 2:25.0.0-2 |
| glance_project | glance | >= 0 < 23.0.1 | 23.0.1 |
| glance_project | glance | >= 24.0.0 < 24.1.1 | 24.1.1 |
| openstack | cinder | <= 19.1.2 | — |
| openstack | cinder | >= 0 < 2:17.0.1-1+deb11u1 | 2:17.0.1-1+deb11u1 |
| openstack | cinder | >= 0 < 2:21.0.0-3 | 2:21.0.0-3 |
| openstack | cinder | >= 0 < 2:21.0.0-3 | 2:21.0.0-3 |
| openstack | cinder | >= 0 < 2:21.0.0-3 | 2:21.0.0-3 |
| openstack | cinder | >= 0 < 19.1.2 | 19.1.2 |
| openstack | cinder | >= 20.0.0 < 20.0.2 | 20.0.2 |
| openstack | cinder | >= 20.0.0 < 20.0.2 | 20.0.2 |
| openstack | glance | < 23.0.1 | 23.0.1 |
| openstack | glance | >= 24.0.0 < 24.1.1 | 24.1.1 |
| openstack | nova | < 27.4.1 | 27.4.1 |
| openstack | nova | < 24.1.2 | 24.1.2 |
| openstack | nova | >= 0 < 2:22.0.1-2+deb11u1 | 2:22.0.1-2+deb11u1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
ghsa5.7MEDIUM
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Cinder regression
vendor_ubuntu·2024-11-07
CVE-2024-32498 Cinder regression
Title: Cinder regression
Summary: USN-6882-1 introduced a regression in Cinder.
USN-6882-1 fixed vulnerabilities in Cinder. The update caused a regression
in certain environments due to incorrect privilege handling. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: Regression VMDK/qcow arbitrary file access
vendor_redhat·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-552 openstack-nova: Regression VMDK/qcow arbitrary file access
openstack-nova: Regression VMDK/qcow arbitrary file access
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
An arbitrary file access flaw was found in Nova. By supplying a RAW format image, a specially crafted QCOW2 image with a backing file path, or a VMDK flat image with a descriptor file path, an authenticated user may conv
Debian
CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
vendor_debian·2024·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Ubuntu
Cinder vulnerability
vendor_ubuntu·2023-02-09
CVE-2022-47951 Cinder vulnerability
Title: Cinder vulnerability
Summary: Cinder could be made to expose sensitive information.
USN-5835-1 fixed vulnerabilities in Cinder. This update provides the
corresponding updates for Ubuntu 18.04 LTS. In addition, a regression was
fixed for Ubuntu 20.04 LTS.
Original advisory details:
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Cinder incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Instructions: After a standard system update you need to restart Cinder to make all the
Ubuntu
Nova vulnerability
vendor_ubuntu·2023-02-09
CVE-2022-47951 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to expose sensitive information.
USN-5835-3 fixed vulnerabilities in Nova. This update provides the
corresponding updates for Ubuntu 18.04 LTS.
Original advisory details:
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Nova incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Cinder vulnerability
vendor_ubuntu·2023-01-31
CVE-2022-47951 Cinder vulnerability
Title: Cinder vulnerability
Summary: Cinder could be made to expose sensitive information.
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Cinder incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Instructions: After a standard system update you need to restart Cinder to make all the
necessary changes.
Ubuntu
Nova vulnerability
vendor_ubuntu·2023-01-31
CVE-2022-47951 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to expose sensitive information.
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that Nova incorrectly handled VMDK image processing. An
authenticated attacker could possibly supply a specially crafted VMDK flat
image and obtain arbitrary files from the server containing sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2023-01-31
CVE-2022-47951 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: OpenStack Glance could be made to expose sensitive information.
Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou
discovered that OpenStack Glance incorrectly handled VMDK image processing.
An authenticated attacker could possibly supply a specially crafted VMDK
flat image and obtain arbitrary files from the server containing sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack: Arbitrary file access through custom VMDK flat descriptor
vendor_redhat·2023-01-24·CVSS 5.7
CVE-2022-47951 [MEDIUM] CWE-552 openstack: Arbitrary file access through custom VMDK flat descriptor
openstack: Arbitrary file access through custom VMDK flat descriptor
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
A flaw was found in OpenStack-nova, Openstack-glance, and Openstack-cinder. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the serv
Debian
CVE-2022-47951: cinder - An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, a...
vendor_debian·2022·CVSS 5.7
CVE-2022-47951 [MEDIUM] CVE-2022-47951: cinder - An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, a...
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
Scope: local
bookworm: resolved (fixed in 2:21.0.0-3)
bullseye: resolved (fixed in 2:17.0.1-1+deb11u1)
forky: resolved (fixed in 2:21.0.0-3)
sid: resolved (fixed in 2:21.0.0-3)
trixie: resolved (fixed in 2:21.0.0-3)
OSV
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
osv·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
GHSA
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
ghsa·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-436 OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
OSV
CVE-2024-40767: In OpenStack Nova before 27
osv·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: In OpenStack Nova before 27
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
OSV
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
osv·2023-01-27
CVE-2022-47951 [MEDIUM] OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
GHSA
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
ghsa·2023-01-27
CVE-2022-47951 [MEDIUM] CWE-22 OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
OSV
CVE-2022-47951: An issue was discovered in OpenStack Cinder before 19
osv·2023-01-26·CVSS 5.7
CVE-2022-47951 [MEDIUM] CVE-2022-47951: An issue was discovered in OpenStack Cinder before 19
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-24708 [LOW] CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24708 :
OpenStack Nova vulnerability analysis and mitigation
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Source : NVD
## 8.2
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
OpenStack Nova
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
E
Wiz
CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-34881 [MEDIUM] CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34881 :
OpenStack Glance vulnerability analysis and mitigation
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Source : NVD
## 5
Score
Published March 31, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
OpenStack Glance
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabil
https://launchpad.net/bugs/1996188https://lists.debian.org/debian-lts-announce/2023/01/msg00040.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00042.htmlhttps://security.openstack.org/ossa/OSSA-2023-002.htmlhttps://www.debian.org/security/2023/dsa-5336https://www.debian.org/security/2023/dsa-5337https://www.debian.org/security/2023/dsa-5338https://launchpad.net/bugs/1996188https://lists.debian.org/debian-lts-announce/2023/01/msg00040.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00042.htmlhttps://security.openstack.org/ossa/OSSA-2023-002.htmlhttps://www.debian.org/security/2023/dsa-5336https://www.debian.org/security/2023/dsa-5337https://www.debian.org/security/2023/dsa-5338
2023-01-26
Published