NA

CVE-2023-2088

Published: 12/05/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack -

Vendor Advisories

Debian Bug report logs - #1035932 CVE-2023-2088 / OSSA-2023-003: Unauthorized volume access through deleted volume attachments Package: src:python-os-brick; Maintainer for src:python-os-brick is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Thu, 11 May 2023 1 ...
Synopsis Critical: Red Hat OpenStack Platform 170 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 170 (Wallaby)Red Hat Product ...
Synopsis Critical: Red Hat OpenStack Platform 130 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 13 (Queens)Red Hat Product Sec ...
Synopsis Critical: Red Hat OpenStack Platform 162 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-nova is now available for Red Hat OpenStackPlatform 162 (Train)Red Hat Product Se ...
概要 Critical: Red Hat OpenStack Platform 161 security update タイプ/重大度 Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems トピック An update for openstack-nova is now available for Red Hat OpenStackPlatform 161 (Train)Red Hat ...
Description<!---->A flaw was found in OpenStack due to an inconsistency between Cinder and Nova This issue can be triggered intentionally or by accident A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder The highest impact is to confidentialityA flaw was found in OpenStack due to an i ...