← Back to CVEs
CVE-2015-7548
N/ADescription
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
CVE Details
CVSS v3.1 ScoreN/A
Published1/12/2016
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0
Affected Products
openstack:nova
Weaknesses (CWE)
CWE-200
References
http://rhn.redhat.com/errata/RHSA-2016-0018.html(secalert@redhat.com)
http://www.securityfocus.com/bid/80176(secalert@redhat.com)
https://security.openstack.org/ossa/OSSA-2016-001.html(secalert@redhat.com)
http://rhn.redhat.com/errata/RHSA-2016-0018.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/80176(af854a3a-2127-422b-91ae-364da2661108)
https://security.openstack.org/ossa/OSSA-2016-001.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.