{"id":"CVE-2014-3641","aliases":["GHSA-qhch-g8qr-p497","PYSEC-2026-791"],"title":"OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability","summary":"OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability","severity":"medium","vendor":"cinder","product":"cinder","ecosystem":"pip","affected":["cinder < 2014.1.3"],"patched":["cinder 2014.1.3"],"published":"2022-05-17","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:39.734477851Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qhch-g8qr-p497","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3641"},{"url":"https://access.redhat.com/errata/RHSA-2014:1787"},{"url":"https://access.redhat.com/errata/RHSA-2014:1788"},{"url":"https://access.redhat.com/security/cve/CVE-2014-3641"},{"url":"https://bugs.launchpad.net/cinder/+bug/1350504"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1141996"},{"url":"https://opendev.org/openstack/cinder"},{"url":"https://web.archive.org/web/20200228053848/http://www.securityfocus.com/bid/70221"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1787.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1788.html"},{"url":"http://seclists.org/oss-sec/2014/q4/78"},{"url":"http://www.ubuntu.com/usn/USN-2405-1"}],"tags":["osv","pip"],"epss":0.01875,"epssPercentile":0.78181,"ingestedAt":"2026-07-08T18:25:52.426Z","slug":"CVE-2014-3641","body":"## Overview\n\nThe (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.\n\n## Affected packages\n\n- `cinder < 2014.1.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cinder 2014.1.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}