cbcvebase.
CVE-2023-2088
published 2023-05-12

CVE-2023-2088: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiancinder< cinder 2:21.1.0-3 (bookworm)cinder 2:21.1.0-3 (bookworm)
debiannova< cinder 2:21.1.0-3 (bookworm)cinder 2:21.1.0-3 (bookworm)
debianpython-glance-store< cinder 2:21.1.0-3 (bookworm)cinder 2:21.1.0-3 (bookworm)
debianpython-os-brick< cinder 2:21.1.0-3 (bookworm)cinder 2:21.1.0-3 (bookworm)
msrcmicrosoft_edge
msrcmicrosoft_edge_extended_stable
msrcmicrosoft_edge_for_android
openstackcinder>= 0 < 2:17.4.0-1~deb11u22:17.4.0-1~deb11u2
openstackcinder>= 0 < 2:21.1.0-32:21.1.0-3
openstackcinder>= 0 < 2:21.1.0-32:21.1.0-3
openstackcinder>= 0 < 2:21.1.0-32:21.1.0-3
openstackcinder>= 0 < 2:20.2.0-0ubuntu1.12:20.2.0-0ubuntu1.1
openstackironic>= 0 < 1:20.1.0-0ubuntu1.11:20.1.0-0ubuntu1.1
openstacknova>= 0 < 2:26.1.0-42:26.1.0-4
openstacknova>= 0 < 2:26.1.0-42:26.1.0-4
openstacknova>= 0 < 2:26.1.0-42:26.1.0-4
openstacknova>= 0 < 3:25.1.1-0ubuntu1.13:25.1.1-0ubuntu1.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM