-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cinder | pip | <= 24.0.0 | |
| glance | pip | <= 28.0.1 | |
| nova | pip | <= 29.0.2 |
The vulnerability stems from missing validation of QCOW2 'data_file' attributes during image processing. Patches in Cinder, Glance, and Nova introduced safety checks in these specific functions to reject images with external data references. The original versions of these functions lacked these critical validations, making them the entry points for the exploit. Code analysis of commit diffs and advisory details confirms these functions were the focal points of the vulnerability.
KEV Misses 88% of Exploited CVEs- Get the report