CVE-2015-1851

Published Jun 25, 2015

Last updated 19 days ago

Overview

Description
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
Source
secalert@redhat.com
NVD status
Modified
Products
ubuntu_linux, icehouse, juno, kilo

Risk scores

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.9
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:C/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-200

Social media

Hype score
Not currently trending

Configurations