CVE-2015-5162High· 7.5▾ TwilightOpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.1%
3.1% → 3.1%
The image parser in OpenStack Cinder prior to 7.0.2, and 8.0.0 and above, prior to 9.0.0; Glance prior to 14.00; and Nova prior to 12.0.4 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. This issue is patched in Cinder 7.0.2 and 9.0.0; Glance 14.0.0; and Nova 12.0.4
cinder < 7.0.2cinder >= 8.0.0, < 9.0.0glance < 14.0.0nova < 12.0.4Upgrade to a patched release:
cinder 7.0.2cinder 9.0.0glance 14.0.0nova 12.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2020-10755Medium· 6.5Openstack cinder Improper handling of ScaleIO backend credentials
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2014-3641MediumOpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2013-4202MediumOpenStack Cinder Denial of Service using XML entities
CVE-2015-1851MediumOpenStack Cinder file disclosure in image convert
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal