{"id":"CVE-2011-3147","aliases":["GHSA-hqfx-4x4w-vmwp","PYSEC-2026-690"],"title":"Openstack nova qcow format could expose host filesystem information","summary":"Openstack nova qcow format could expose host filesystem information","severity":"low","cvss":2.8,"cvssVector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","vendor":"nova","product":"nova","ecosystem":"pip","affected":["nova < 12.0.0a0"],"patched":["nova 12.0.0a0"],"published":"2022-04-22","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hqfx-4x4w-vmwp","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-3147"},{"url":"https://github.com/openstack/nova/commit/ff9d353b2f4fee469e530fbc8dc231a41f6fed84"},{"url":"https://bugs.launchpad.net/nova/+bug/853330"},{"url":"http://bazaar.launchpad.net/~hudson-openstack/nova/trunk/revision/1604"}],"tags":["osv","pip"],"epss":0.0074,"epssPercentile":0.52692,"ingestedAt":"2026-07-08T18:25:50.308Z","slug":"CVE-2011-3147","body":"## Overview\n\nVersions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.\n\n## Affected packages\n\n- `nova < 12.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nova 12.0.0a0`","depth":"sunlit","depthScore":16,"depthScoreParts":{"impact":15.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}