CVE-2014-3641Medium▾ SunlitOpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.9%
1.9% → 1.9%
Last analysed / modified upstream
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
cinder < 2014.1.3Upgrade to a patched release:
cinder 2014.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2020-10755Medium· 6.5Openstack cinder Improper handling of ScaleIO backend credentials
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2013-4202MediumOpenStack Cinder Denial of Service using XML entities
CVE-2015-5162High· 7.5OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
CVE-2015-1851MediumOpenStack Cinder file disclosure in image convert
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal