CVE-2014-3641
openstack-cinder: Cinder-volume host data leak to virtual machine instance
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Los controladores (1) GlusterFS y (2) Linux Smbfs en OpenStack Cinder anterior a 2014.1.3 permiten a usuarios remotos autenticados obtener datos de ficheros del anfitrión Cinder-volume mediante el clonación y adjunto de un volumen con una cabecera qcow2 manipulada.
OpenStack Block Storage manages block storage mounting and the presentation of such mounted block storage to instances. The backend physical storage can consist of local disks, or Fiber Channel, iSCSI, and NFS mounts attached to Compute nodes. In addition, Block Storage supports volume backups, and snapshots for temporary save and restore operations. Programatic management is available via Block Storage’s API. A flaw was found in the GlusterFS and Linux smbfs drivers for OpenStack Block Storage. A remote attacker could use this flaw to disclose an arbitrary file from the cinder-volume host to a virtual instance by cloning and attaching a volume with a malicious qcow2 header.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-10-08 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://seclists.org/oss-sec/2014/q4/78 | Mailing List |
|
http://www.securityfocus.com/bid/70221 | Vdb Entry | |
https://bugs.launchpad.net/cinder/+bug/1350504 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-1787.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2014-1788.html | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-2405-1 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2014-3641 | 2014-11-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1141996 | 2014-11-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Cinder Search vendor "Openstack" for product "Cinder" | <= 2014.1.2 Search vendor "Openstack" for product "Cinder" and version " <= 2014.1.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Cinder Search vendor "Openstack" for product "Cinder" | 2014.1.1 Search vendor "Openstack" for product "Cinder" and version "2014.1.1" | - |
Affected
|