CVE-2015-1851
cinder - security update
EPSS 2.6%
Description
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
How to fix CVE-2015-1851
To remediate CVE-2015-1851, upgrade the affected package to a fixed version below.
- PyPI/cinder—upgrade to 7.0.0a0 or later
- PyPI/cinder—upgrade to 7.0.0a0 or later
Is CVE-2015-1851 being exploited?
Low — EPSS is 2.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 7.0.0a0
- from 0, < 7.0.0a0