QID 691387

Date Published: 2024-01-04

QID 691387: Free Berkeley Software Distribution (FreeBSD) Security Update for Cinder (f4a94232-7864-4afb-bbf9-ff2dc8e288d1)

FreeBSD has released a security update for Cinder to fix the vulnerabilities.

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to FreeBSD security advisory f4a94232-7864-4afb-bbf9-ff2dc8e288d1 for updates and patch information.
    Vendor References

    CVEs related to QID 691387

    Software Advisories
    Advisory ID Software Component Link
    f4a94232-7864-4afb-bbf9-ff2dc8e288d1 URL Logo vuxml.freebsd.org/freebsd/f4a94232-7864-4afb-bbf9-ff2dc8e288d1.html