Arbitrary File Read Vulnerability in OpenStack Compute (Nova)

Arbitrary File Read Vulnerability in OpenStack Compute (Nova)

CVE-2015-7548 · LOW Severity

AV:N/AC:H/AU:S/C:P/I:N/A:N

OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

Learn more about our User Device Pen Test.