Description: | Duncan Thomas discovered that OpenStack Cinder did not properly track thefile format when using the GlusterFS of Smbfs drivers. A remoteauthenticated user could exploit this to potentially obtain file contentsfrom the compute host. (CVE-2014-3641)Amrith Kumar discovered that OpenStack Cinder did not properly sanitize logmessage contents. Under certain circumstances, a local attacker with readaccess to Cinder log files could obtain access to sensitive information.(CVE-2014-7230) |