Data Exposure in OpenStack Cinder, Glance, and Nova Due to VMDK File Manipulation
CVE-2022-47951
5.7MEDIUM
What is CVE-2022-47951?
An issue within OpenStack's Cinder, Glance, and Nova components allows authenticated users to exploit specially crafted VMDK flat images. By referencing specific backing file paths, these users can potentially retrieve sensitive data stored on the server, leading to unauthorized access and data exposure risks.