cbcvebase.
CVE-2024-32498
published 2024-07-05

CVE-2024-32498: An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2…

PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.83%
53.7th percentile
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiancinder< cinder 2:21.3.1-1~deb12u1 (bookworm)cinder 2:21.3.1-1~deb12u1 (bookworm)
debianglance< cinder 2:21.3.1-1~deb12u1 (bookworm)cinder 2:21.3.1-1~deb12u1 (bookworm)
debiannova< cinder 2:21.3.1-1~deb12u1 (bookworm)cinder 2:21.3.1-1~deb12u1 (bookworm)
debiannova
glance_projectglance>= 0 < 2:21.1.0-1+deb11u22:21.1.0-1+deb11u2
glance_projectglance>= 0 < 2:25.1.0-2+deb12u12:25.1.0-2+deb12u1
glance_projectglance>= 0 < 2:28.0.1-3+deb12u12:28.0.1-3+deb12u1
glance_projectglance>= 0 < 2:28.0.1-3+deb12u12:28.0.1-3+deb12u1
glance_projectglance0 – 28.0.1
openstackcinder< 22.1.322.1.3
openstackcinder
openstackcinder>= 0 < 2:17.4.0-1~deb11u22:17.4.0-1~deb11u2
openstackcinder>= 0 < 2:21.3.1-1~deb12u12:21.3.1-1~deb12u1
openstackcinder>= 0 < 2:24.0.0-52:24.0.0-5
openstackcinder>= 0 < 2:24.0.0-52:24.0.0-5
openstackcinder0 – 24.0.0
openstackcinder>= 23.0.0 < 23.1.123.1.1
openstackglance< 26.0.126.0.1
openstackglance
openstackglance>= 28.0.0 < 28.0.228.0.2
openstacknova< 27.4.127.4.1
openstacknova< 27.3.127.3.1
openstacknova>= 0 < 2:22.4.0-1~deb11u52:22.4.0-1~deb11u5
openstacknova>= 0 < 2:26.2.2-1~deb12u32:26.2.2-1~deb12u3
openstacknova>= 0 < 2:29.0.2-42:29.0.2-4

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ghsa5.7MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.