---
id: CVE-2015-1851
aliases:
  - GHSA-9hcj-h2qc-689p
  - PYSEC-2026-789
title: OpenStack Cinder file disclosure in image convert
summary: OpenStack Cinder file disclosure in image convert
severity: medium
vendor: cinder
product: cinder
ecosystem: pip
affected:
  - cinder < 7.0.0a0
patched:
  - cinder 7.0.0a0
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-9hcj-h2qc-689p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2015-1851'
  - url: >-
      https://github.com/openstack/cinder/commit/9634b76ba5886d6c2f2128d550cb005dabf48213
  - url: >-
      https://github.com/openstack/cinder/commit/b1143ee45323e63b965a3710f9063e65b252c978
  - url: >-
      https://github.com/openstack/cinder/commit/bc0549e08b010edb863d409d80114aa78d317a61
  - url: >-
      https://github.com/openstack/cinder/commit/d31c937c566005dedf41a60c6b5bd5e7b26f221b
  - url: 'https://bugs.launchpad.net/cinder/+bug/1415087'
  - url: 'https://github.com/openstack/cinder'
  - url: >-
      http://lists.openstack.org/pipermail/openstack-announce/2015-June/000367.html
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1206.html'
  - url: 'http://www.debian.org/security/2015/dsa-3292'
  - url: 'http://www.openwall.com/lists/oss-security/2015/06/13/1'
  - url: 'http://www.openwall.com/lists/oss-security/2015/06/17/2'
  - url: 'http://www.openwall.com/lists/oss-security/2015/06/17/7'
  - url: 'http://www.ubuntu.com/usn/USN-2703-1'
tags:
  - osv
  - pip
epss: 0.0264
epssPercentile: 0.8491
ingestedAt: '2026-07-08T18:25:48.003Z'
---

## Overview

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.

## Affected packages

- `cinder < 7.0.0a0`

## Remediation

Upgrade to a patched release:

- `cinder 7.0.0a0`
