Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2015-1851

MEDIUM severity · CVSS 6.8 · Information disclosure
6.8CVSS MEDIUM

Summary

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)3%

AV:N/AC:L/Au:S/C:C/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.