Unauthorized Access to Sensitive Data via Custom QCOW2 External Data in OpenStack Cinder, Glance, and Nova
CVE-2024-32498
Key Information:
Badges
What is CVE-2024-32498?
A critical security vulnerability (CVE-2024-32498) has been discovered in OpenStack, affecting the Cinder, Glance, and Nova components. The flaw allows attackers to gain unauthorized access to sensitive data by supplying a crafted QCOW2 image that references a specific data file path, potentially exposing confidential information. The vulnerability poses a risk of unauthorized access, data breaches, and the compromise of cloud environments, with the potential for significant legal and financial consequences. It has been classified as critical with a high severity score. Mitigation patches have been released by Red Hat and the OpenStack community, and system administrators are advised to apply these updates promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
News Articles
Kritik OpenStack Güvenlik Açığı (CVE-2024-32498): Bulut Verileri Büyük Tehlikede! (CVSS 8.8) - ÇözümPark
Kritik OpenStack Güvenlik Açığı (CVE-2024-32498): Bulut Verileri Büyük Tehlikede! (CVSS 8.8)
Critical OpenStack Arbitrary File Access Flaw Exposes Cloud Data to Hackers
The flaw tracked as CVE-2024-32498, allows authenticated attackers to gain unauthorized access to arbitrary files on the host system, potentially exposing sensitive data.
References
CVSS V3.1
Timeline
Vulnerability published
- 📰
First article discovered by CybersecurityNews
