{"id":"CVE-2015-1851","aliases":["GHSA-9hcj-h2qc-689p","PYSEC-2026-789"],"title":"OpenStack Cinder file disclosure in image convert","summary":"OpenStack Cinder file disclosure in image convert","severity":"medium","vendor":"cinder","product":"cinder","ecosystem":"pip","affected":["cinder < 7.0.0a0"],"patched":["cinder 7.0.0a0"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9hcj-h2qc-689p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1851"},{"url":"https://github.com/openstack/cinder/commit/9634b76ba5886d6c2f2128d550cb005dabf48213"},{"url":"https://github.com/openstack/cinder/commit/b1143ee45323e63b965a3710f9063e65b252c978"},{"url":"https://github.com/openstack/cinder/commit/bc0549e08b010edb863d409d80114aa78d317a61"},{"url":"https://github.com/openstack/cinder/commit/d31c937c566005dedf41a60c6b5bd5e7b26f221b"},{"url":"https://bugs.launchpad.net/cinder/+bug/1415087"},{"url":"https://github.com/openstack/cinder"},{"url":"http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1206.html"},{"url":"http://www.debian.org/security/2015/dsa-3292"},{"url":"http://www.openwall.com/lists/oss-security/2015/06/13/1"},{"url":"http://www.openwall.com/lists/oss-security/2015/06/17/2"},{"url":"http://www.openwall.com/lists/oss-security/2015/06/17/7"},{"url":"http://www.ubuntu.com/usn/USN-2703-1"}],"tags":["osv","pip"],"epss":0.0264,"epssPercentile":0.84849,"ingestedAt":"2026-07-08T18:25:48.003Z","slug":"CVE-2015-1851","body":"## Overview\n\nOpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.\n\n## Affected packages\n\n- `cinder < 7.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `cinder 7.0.0a0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}