CVE-2024-32498
published 2024-07-05CVE-2024-32498: An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.83%
53.7th percentile
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinder | < cinder 2:21.3.1-1~deb12u1 (bookworm) | cinder 2:21.3.1-1~deb12u1 (bookworm) |
| debian | glance | < cinder 2:21.3.1-1~deb12u1 (bookworm) | cinder 2:21.3.1-1~deb12u1 (bookworm) |
| debian | nova | < cinder 2:21.3.1-1~deb12u1 (bookworm) | cinder 2:21.3.1-1~deb12u1 (bookworm) |
| debian | nova | — | — |
| glance_project | glance | >= 0 < 2:21.1.0-1+deb11u2 | 2:21.1.0-1+deb11u2 |
| glance_project | glance | >= 0 < 2:25.1.0-2+deb12u1 | 2:25.1.0-2+deb12u1 |
| glance_project | glance | >= 0 < 2:28.0.1-3+deb12u1 | 2:28.0.1-3+deb12u1 |
| glance_project | glance | >= 0 < 2:28.0.1-3+deb12u1 | 2:28.0.1-3+deb12u1 |
| glance_project | glance | 0 – 28.0.1 | — |
| openstack | cinder | < 22.1.3 | 22.1.3 |
| openstack | cinder | — | — |
| openstack | cinder | >= 0 < 2:17.4.0-1~deb11u2 | 2:17.4.0-1~deb11u2 |
| openstack | cinder | >= 0 < 2:21.3.1-1~deb12u1 | 2:21.3.1-1~deb12u1 |
| openstack | cinder | >= 0 < 2:24.0.0-5 | 2:24.0.0-5 |
| openstack | cinder | >= 0 < 2:24.0.0-5 | 2:24.0.0-5 |
| openstack | cinder | 0 – 24.0.0 | — |
| openstack | cinder | >= 23.0.0 < 23.1.1 | 23.1.1 |
| openstack | glance | < 26.0.1 | 26.0.1 |
| openstack | glance | — | — |
| openstack | glance | >= 28.0.0 < 28.0.2 | 28.0.2 |
| openstack | nova | < 27.4.1 | 27.4.1 |
| openstack | nova | < 27.3.1 | 27.3.1 |
| openstack | nova | >= 0 < 2:22.4.0-1~deb11u5 | 2:22.4.0-1~deb11u5 |
| openstack | nova | >= 0 < 2:26.2.2-1~deb12u3 | 2:26.2.2-1~deb12u3 |
| openstack | nova | >= 0 < 2:29.0.2-4 | 2:29.0.2-4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa5.7MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
osv·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
GHSA
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
ghsa·2024-07-24·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-436 OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
OSV
CVE-2024-40767: In OpenStack Nova before 27
osv·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: In OpenStack Nova before 27
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
OSV
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
osv·2024-07-05
CVE-2024-32498 [HIGH] OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
GHSA
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
ghsa·2024-07-05
CVE-2024-32498 [HIGH] CWE-200 OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
OSV
CVE-2024-32498: An issue was discovered in OpenStack Cinder through 24
osv·2024-07-05·CVSS 6.5
CVE-2024-32498 [MEDIUM] CVE-2024-32498: An issue was discovered in OpenStack Cinder through 24
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
Ubuntu
OpenStack Glance vulnerabilities
vendor_ubuntu·2026-04-22·CVSS 6.5
CVE-2024-32498 [MEDIUM] OpenStack Glance vulnerabilities
Title: OpenStack Glance vulnerabilities
Summary: Several security issues were fixed in OpenStack Glance.
Martin Kaesberger discovered that OpenStack Glance's image processing could
return the contents of arbitrary files. An attacker could possibly use this
issue to exfiltrate sensitive data. This issue only affected Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. (CVE-2024-32498)
Hyeongeun Ji and Abhishek Kekane discovered several server-side request
forgery vulnerabilities in OpenStack Glance's image import. An attacker
could possibly use this issue to bypass URL validation checks and redirect
to internal services. This issue only affected Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. (CVE-2026-34881)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Cinder regression
vendor_ubuntu·2024-11-07
CVE-2024-32498 Cinder regression
Title: Cinder regression
Summary: USN-6882-1 introduced a regression in Cinder.
USN-6882-1 fixed vulnerabilities in Cinder. The update caused a regression
in certain environments due to incorrect privilege handling. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: Regression VMDK/qcow arbitrary file access
vendor_redhat·2024-07-23·CVSS 5.7
CVE-2024-40767 [MEDIUM] CWE-552 openstack-nova: Regression VMDK/qcow arbitrary file access
openstack-nova: Regression VMDK/qcow arbitrary file access
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
An arbitrary file access flaw was found in Nova. By supplying a RAW format image, a specially crafted QCOW2 image with a backing file path, or a VMDK flat image with a descriptor file path, an authenticated user may conv
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2024-07-08
CVE-2024-32498 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: OpenStack Glance would allow unintended access to files over the network.
Martin Kaesberger discovered that Glance incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Nova vulnerability
vendor_ubuntu·2024-07-08
CVE-2024-32498 Nova vulnerability
Title: Nova vulnerability
Summary: Nova would allow unintended access to files over the network.
Martin Kaesberger discovered that Nova incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Cinder vulnerability
vendor_ubuntu·2024-07-08
CVE-2024-32498 Cinder vulnerability
Title: Cinder vulnerability
Summary: Cinder would allow unintended access to files over the network.
Martin Kaesberger discovered that Cinder incorrectly handled QCOW2 image
processing. An authenticated user could use this issue to access arbitrary
files on the server, possibly exposing sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: malicious qcow2/vmdk images
vendor_redhat·2024-07-02·CVSS 6.5
CVE-2024-32498 [MEDIUM] CWE-22 OpenStack: malicious qcow2/vmdk images
OpenStack: malicious qcow2/vmdk images
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
An input validation flaw was discovered in how multiple OpenStack services validate images with backing file references. An authenticated attacker could provide a malicious image via upload, or by creating and modifying an image fro
Debian
CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
vendor_debian·2024·CVSS 5.7
CVE-2024-40767 [MEDIUM] CVE-2024-40767: nova - In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supp...
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2024-32498: cinder - An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2...
vendor_debian·2024·CVSS 6.5
CVE-2024-32498 [MEDIUM] CVE-2024-32498: cinder - An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2...
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
Scope: local
bookworm: resolved (fixed in 2:21.3.1-1~deb12u1)
bullseye: resolved (fixed in 2:17.4.0-1~deb11u2)
forky: resolved (fixed in 2:24.0.0-5)
sid: resolved (fixed in 2:24.0.0-5)
trixie: resolved (fixed in 2:24.0.0-5)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-24708 [LOW] CVE-2026-24708 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24708 :
OpenStack Nova vulnerability analysis and mitigation
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.
Source : NVD
## 8.2
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
OpenStack Nova
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
E
Wiz
CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-34881 [MEDIUM] CVE-2026-34881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34881 :
OpenStack Glance vulnerability analysis and mitigation
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
Source : NVD
## 5
Score
Published March 31, 2026
Severity MEDIUM
CNA Score 5.0
Affected Technologies
OpenStack Glance
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabil
http://www.openwall.com/lists/oss-security/2024/07/02/2https://launchpad.net/bugs/2059809https://security.openstack.org/ossa/OSSA-2024-001.htmlhttps://www.openwall.com/lists/oss-security/2024/07/02/2http://www.openwall.com/lists/oss-security/2024/07/02/2https://launchpad.net/bugs/2059809https://lists.debian.org/debian-lts-announce/2024/09/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00017.htmlhttps://www.openwall.com/lists/oss-security/2024/07/02/2
2024-07-05
Published