Vulnerability Name:

CVE-2015-1851 (CCN-103916)

Assigned:2015-06-13
Published:2015-06-13
Updated:2016-12-28
Summary:OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
CVSS v3 Severity:6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-1851

Source: MLIST
Type: Vendor Advisory
[openstack-announce] 20150616 [OSSA 2015-011.1] Cinder host file disclosure through qcow2 backing file (CVE-2015-1851) ERRATA 1

Source: REDHAT
Type: UNKNOWN
RHSA-2015:1206

Source: CCN
Type: oss-security Mailing List, Wed, 17 Jun 2015 06:43:00 -0700
Re: [OSSA 2015-011] Cinder host file disclosure through qcow2 backing file (CVE-2015-1851)

Source: DEBIAN
Type: UNKNOWN
DSA-3292

Source: CCN
Type: IBM Security Bulletin T1023146
Openstack Cinder and Horizon vulnerabilities affect IBM Cloud Manager with OpenStack (CVE-2015-1851 CVE-2015-3219)

Source: CCN
Type: IBM Security Bulletin N1020980
IBM PowerVC is impacted by OpenStack Cinder information disclosure vulneraility (CVE-2015-1851)

Source: MLIST
Type: UNKNOWN
[oss-security] 20150613 CVE-2015-1850: OpenStack Cinder/Nova: Format-guessing and file disclosure in image convert

Source: MLIST
Type: UNKNOWN
[oss-security] 20150617 Re: [OSSA 2015-011] Cinder host file disclosure through qcow2 backing file (CVE-2015-1850)

Source: MLIST
Type: UNKNOWN
[oss-security] 20150617 Re: [OSSA 2015-011] Cinder host file disclosure through qcow2 backing file (CVE-2015-1850)

Source: UBUNTU
Type: UNKNOWN
USN-2703-1

Source: CCN
Type: Launchpad Bug #1415087
Format-guessing and file disclosure in image convert (CVE-2015-1850)

Source: CONFIRM
Type: UNKNOWN
https://bugs.launchpad.net/cinder/+bug/1415087

Source: CCN
Type: Red Hat Bugzilla – Bug 1231817
(CVE-2015-1851) CVE-2015-1851 openstack-cinder: Host file disclosure through qcow2 backing file

Source: XF
Type: UNKNOWN
openstack-cinder-cve20151851-info-disc(103916)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-1851

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:openstack:icehouse:*:*:*:*:*:*:*:* (Version <= 2014.1.4)
  • OR cpe:/a:openstack:juno:2014.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:juno:2014.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:juno:2014.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:kilo:2015.1.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openstack:cinder:2014.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:openstack:cinder:2014.2.1:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_manager:4.1.0:*:*:*:*:openstack:*:*
  • OR cpe:/a:ibm:cloud_manager:4.2.0:*:*:*:*:openstack:*:*
  • OR cpe:/a:ibm:cloud_manager:4.3.0:*:*:*:*:openstack:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.cisecurity:def:233
    P
    DSA-3292-1 -- cinder -- security update
    2016-02-08
    oval:com.ubuntu.trusty:def:20151851000
    V
    CVE-2015-1851 on Ubuntu 14.04 LTS (trusty) - medium.
    2015-06-25
    BACK
    canonical ubuntu linux 15.04
    openstack icehouse *
    openstack juno 2014.2
    openstack juno 2014.2.2
    openstack juno 2014.2.3
    openstack kilo 2015.1.0
    openstack cinder 2014.1.3
    openstack cinder 2014.2.1
    ibm cloud manager 4.1.0
    ibm cloud manager 4.2.0
    ibm cloud manager 4.3.0