OpenStack Nova 2015.1.2

CPE Details

OpenStack Nova 2015.1.2
2015.1.2
2018-11-14
17h23 +00:00
2018-11-14
17h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:openstack:nova:2015.1.2:*:*:*:*:*:*:*

Informations

Vendor

openstack

Product

nova

Version

2015.1.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-2140 2016-04-12 12h00 +00:00 The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
5.3
Medium
CVE-2015-8749 2016-01-15 18h00 +00:00 The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.
5.9
Medium
CVE-2015-7548 2016-01-12 18h00 +00:00 OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
3.5
Low