CVE-2023-2088
published 2023-05-12CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.20%
64.7th percentile
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2:21.1.0-3 (bookworm) | cinder 2:21.1.0-3 (bookworm) |
| debian | nova | < cinder 2:21.1.0-3 (bookworm) | cinder 2:21.1.0-3 (bookworm) |
| debian | python-glance-store | < cinder 2:21.1.0-3 (bookworm) | cinder 2:21.1.0-3 (bookworm) |
| debian | python-os-brick | < cinder 2:21.1.0-3 (bookworm) | cinder 2:21.1.0-3 (bookworm) |
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
| msrc | microsoft_edge_for_android | — | — |
| openstack | cinder | >= 0 < 2:17.4.0-1~deb11u2 | 2:17.4.0-1~deb11u2 |
| openstack | cinder | >= 0 < 2:21.1.0-3 | 2:21.1.0-3 |
| openstack | cinder | >= 0 < 2:21.1.0-3 | 2:21.1.0-3 |
| openstack | cinder | >= 0 < 2:21.1.0-3 | 2:21.1.0-3 |
| openstack | cinder | >= 0 < 2:20.2.0-0ubuntu1.1 | 2:20.2.0-0ubuntu1.1 |
| openstack | ironic | >= 0 < 1:20.1.0-0ubuntu1.1 | 1:20.1.0-0ubuntu1.1 |
| openstack | nova | >= 0 < 2:26.1.0-4 | 2:26.1.0-4 |
| openstack | nova | >= 0 < 2:26.1.0-4 | 2:26.1.0-4 |
| openstack | nova | >= 0 < 2:26.1.0-4 | 2:26.1.0-4 |
| openstack | nova | >= 0 < 3:25.1.1-0ubuntu1.1 | 3:25.1.1-0ubuntu1.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_msrc8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2023-11-14·CVSS 6.6
CVE-2023-36008 [MEDIUM] CWE-416 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.72
11/16/2023
119.0.6045.159/.160
Extended Stable
118.0.2088.109
11/16/2023
118.0.5993.144
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in whi
Microsoft
Chromium: CVE-2023-5996 Use after free in WebAudio
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5996 [HIGH] Chromium: CVE-2023-5996 Use after free in WebAudio
Chromium: CVE-2023-5996 Use after free in WebAudio
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.58
11/09/2023
119.0.6045.123/.124
Extended Stable
118.0.2088.102
11/09/2023
118.0.5993.136
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsof
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-36029 [MEDIUM] Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.44
11/02/2023
119.0.6045.105/.106
Extended Stable
118.0.2088.88
11/02/2023
118.0.5993.
Microsoft
Chromium: CVE-2023-5481 Inappropriate implementation in Downloads
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5481 [MEDIUM] Chromium: CVE-2023-5481 Inappropriate implementation in Downloads
Chromium: CVE-2023-5481 Inappropriate implementation in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerabl
Microsoft
Chromium: CVE-2023-5483 Inappropriate implementation in Intents
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5483 [MEDIUM] Chromium: CVE-2023-5483 Inappropriate implementation in Intents
Chromium: CVE-2023-5483 Inappropriate implementation in Intents
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
Microsoft
Chromium: CVE-2023-5487 Inappropriate implementation in Fullscreen
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5487 [MEDIUM] Chromium: CVE-2023-5487 Inappropriate implementation in Fullscreen
Chromium: CVE-2023-5487 Inappropriate implementation in Fullscreen
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerab
Microsoft
Chromium: CVE-2023-5475 Inappropriate implementation in DevTools
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5475 [MEDIUM] Chromium: CVE-2023-5475 Inappropriate implementation in DevTools
Chromium: CVE-2023-5475 Inappropriate implementation in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable
Microsoft
Chromium: CVE-2023-5476 Use after free in Blink History
vendor_msrc·2023-10-10·CVSS 8.8
CVE-2023-5476 [HIGH] Chromium: CVE-2023-5476 Use after free in Blink History
Chromium: CVE-2023-5476 Use after free in Blink History
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can
Microsoft
Chromium: CVE-2023-5218 Use after free in Site Isolation
vendor_msrc·2023-10-10·CVSS 8.8
CVE-2023-5218 [HIGH] Chromium: CVE-2023-5218 Use after free in Site Isolation
Chromium: CVE-2023-5218 Use after free in Site Isolation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How ca
Microsoft
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-36409 [MEDIUM] Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Enclave memory read - unprivileged write to enclave memory from a host application, which can leak memory contents of the enclave.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker who successfully exploits the vulnerabi
Microsoft
Chromium: CVE-2023-5486 Inappropriate implementation in Input
vendor_msrc·2023-10-10·CVSS 4.3
CVE-2023-5486 [MEDIUM] Chromium: CVE-2023-5486 Inappropriate implementation in Input
Chromium: CVE-2023-5486 Inappropriate implementation in Input
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
H
Microsoft
Chromium: CVE-2023-5485 Inappropriate implementation in Autofill
vendor_msrc·2023-10-10·CVSS 4.3
CVE-2023-5485 [MEDIUM] Chromium: CVE-2023-5485 Inappropriate implementation in Autofill
Chromium: CVE-2023-5485 Inappropriate implementation in Autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable
Microsoft
Chromium: CVE-2023-5477 Inappropriate implementation in Installer
vendor_msrc·2023-10-10·CVSS 4.3
CVE-2023-5477 [MEDIUM] Chromium: CVE-2023-5477 Inappropriate implementation in Installer
Chromium: CVE-2023-5477 Inappropriate implementation in Installer
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerabl
Microsoft
Chromium: CVE-2023-5478 Inappropriate implementation in Autofill
vendor_msrc·2023-10-10·CVSS 4.3
CVE-2023-5478 [MEDIUM] Chromium: CVE-2023-5478 Inappropriate implementation in Autofill
Chromium: CVE-2023-5478 Inappropriate implementation in Autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable
Microsoft
Chromium: CVE-2023-5479 Inappropriate implementation in Extensions API
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5479 [MEDIUM] Chromium: CVE-2023-5479 Inappropriate implementation in Extensions API
Chromium: CVE-2023-5479 Inappropriate implementation in Extensions API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vuln
Microsoft
Chromium: CVE-2023-5474 Heap buffer overflow in PDF
vendor_msrc·2023-10-10·CVSS 8.8
CVE-2023-5474 [HIGH] Chromium: CVE-2023-5474 Heap buffer overflow in PDF
Chromium: CVE-2023-5474 Heap buffer overflow in PDF
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I s
Microsoft
Chromium: CVE-2023-5473 Use after free in Cast
vendor_msrc·2023-10-10·CVSS 6.3
CVE-2023-5473 [MEDIUM] Chromium: CVE-2023-5473 Use after free in Cast
Chromium: CVE-2023-5473 Use after free in Cast
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see th
Microsoft
Chromium: CVE-2023-5484 Inappropriate implementation in Navigation
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5484 [MEDIUM] Chromium: CVE-2023-5484 Inappropriate implementation in Navigation
Chromium: CVE-2023-5484 Inappropriate implementation in Navigation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
118.0.2088.46
118.0.5993.70/.71
10/13/2023
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerab
Microsoft
Adobe: CVE-2023-44323 Adobe PDF Remote Code Execution Vulnerability
vendor_msrc·2023-10-10·CVSS 5.5
CVE-2023-44323 [MEDIUM] Adobe: CVE-2023-44323 Adobe PDF Remote Code Execution Vulnerability
Adobe: CVE-2023-44323 Adobe PDF Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
118.0.2088.76
10/27/2023
118.0.5993.117/.118
FAQ: Why is this Adobe CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Adobe software which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Adobe: Adobe
Adobe Systems Inco
Ubuntu
OpenStack vulnerability
vendor_ubuntu·2023-07-24
CVE-2023-2088 OpenStack vulnerability
Title: OpenStack vulnerability
Summary: OpenStack could be made to expose sensitive information.
Jan Wasilewski and Gorka Eguileor discovered that OpenStack incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes, please see the upstream
advisory and the other links below for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
https://discourse.ubuntu.com/t/cve-2023-2088-for-charmed-openstack/37051
https://lists.openstack.org/pipermail/openstack-discuss/2023-July/034439.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Nova vulnerability
vendor_ubuntu·2023-05-11
CVE-2023-2088 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to expose sensitive information.
Jan Wasilewski and Gorka Eguileor discovered that Nova incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes to be completely effective,
please see the upstream advisory for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Cinder vulnerability
vendor_ubuntu·2023-05-11
CVE-2023-2088 Cinder vulnerability
Title: Cinder vulnerability
Summary: Cinder could be made to expose sensitive information.
Jan Wasilewski and Gorka Eguileor discovered that Cinder incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes to be completely effective,
please see the upstream advisory for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
os-brick vulnerability
vendor_ubuntu·2023-05-11
CVE-2023-2088 os-brick vulnerability
Title: os-brick vulnerability
Summary: os-brick could be made to expose sensitive information.
Jan Wasilewski and Gorka Eguileor discovered that os-brick incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes to be completely effective,
please see the upstream advisory for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Glance_store vulnerability
vendor_ubuntu·2023-05-11
CVE-2023-2088 Glance_store vulnerability
Title: Glance_store vulnerability
Summary: Glance_store could be made to expose sensitive information.
Jan Wasilewski and Gorka Eguileor discovered that Glance_store incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes to be completely effective,
please see the upstream advisory for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-cinder: silently access other user's volumes
vendor_redhat·2023-05-10·CVSS 6.5
CVE-2023-2088 [MEDIUM] CWE-826 openstack-cinder: silently access other user's volumes
openstack-cinder: silently access other user's volumes
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
Statement: There are two ways this flaw can be triggered:
Intentional Type - A malicious user could use Cinder to detach their own volume. As Nova is not made
Debian
CVE-2023-2088: cinder - A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. T...
vendor_debian·2023·CVSS 6.5
CVE-2023-2088 [MEDIUM] CVE-2023-2088: cinder - A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. T...
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
Scope: local
bookworm: resolved (fixed in 2:21.1.0-3)
bullseye: resolved (fixed in 2:17.4.0-1~deb11u2)
forky: resolved (fixed in 2:21.1.0-3)
sid: resolved (fixed in 2:21.1.0-3)
trixie: resolved (fixed in 2:21.1.0-3)
OSV
cinder, ironic, nova, python-glance-store, python-os-brick vulnerability
osv·2023-07-24
cinder, ironic, nova, python-glance-store, python-os-brick vulnerability
cinder, ironic, nova, python-glance-store, python-os-brick vulnerability
Jan Wasilewski and Gorka Eguileor discovered that OpenStack incorrectly
handled deleted volume attachments. An authenticated user or attacker could
possibly use this issue to gain access to sensitive information.
This update may require configuration changes, please see the upstream
advisory and the other links below for more information:
https://security.openstack.org/ossa/OSSA-2023-003.html
https://discourse.ubuntu.com/t/cve-2023-2088-for-charmed-openstack/37051
https://lists.openstack.org/pipermail/openstack-discuss/2023-July/034439.html
GHSA
GHSA-fvf4-jv3j-73mq: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova
ghsa_unreviewed·2023-05-12
CVE-2023-2088 [MEDIUM] CWE-200 GHSA-fvf4-jv3j-73mq: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
OSV
CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova
osv·2023-05-12·CVSS 6.5
CVE-2023-2088 [MEDIUM] CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
No detection rules found.
No writeups or analysis indexed.
2023-05-12
Published