Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-40767

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-40767
  • Openstack » Nova » Version: N/A
    cpe:2.3:a:openstack:nova:-
  • Openstack » Nova » Version: 0.9.0
    cpe:2.3:a:openstack:nova:0.9.0
  • Openstack » Nova » Version: 12.0.0
    cpe:2.3:a:openstack:nova:12.0.0
  • Openstack » Nova » Version: 12.0.1
    cpe:2.3:a:openstack:nova:12.0.1
  • Openstack » Nova » Version: 12.0.2
    cpe:2.3:a:openstack:nova:12.0.2
  • Openstack » Nova » Version: 12.0.3
    cpe:2.3:a:openstack:nova:12.0.3
  • Openstack » Nova » Version: 12.0.4
    cpe:2.3:a:openstack:nova:12.0.4
  • Openstack » Nova » Version: 12.0.5
    cpe:2.3:a:openstack:nova:12.0.5
  • Openstack » Nova » Version: 12.0.6
    cpe:2.3:a:openstack:nova:12.0.6
  • Openstack » Nova » Version: 13.0.0
    cpe:2.3:a:openstack:nova:13.0.0
  • Openstack » Nova » Version: 13.1.0
    cpe:2.3:a:openstack:nova:13.1.0
  • Openstack » Nova » Version: 13.1.1
    cpe:2.3:a:openstack:nova:13.1.1
  • Openstack » Nova » Version: 13.1.2
    cpe:2.3:a:openstack:nova:13.1.2
  • Openstack » Nova » Version: 13.1.3
    cpe:2.3:a:openstack:nova:13.1.3
  • Openstack » Nova » Version: 13.1.4
    cpe:2.3:a:openstack:nova:13.1.4
  • Openstack » Nova » Version: 14.0.0
    cpe:2.3:a:openstack:nova:14.0.0
  • Openstack » Nova » Version: 14.0.1
    cpe:2.3:a:openstack:nova:14.0.1
  • Openstack » Nova » Version: 14.0.10
    cpe:2.3:a:openstack:nova:14.0.10
  • Openstack » Nova » Version: 14.0.2
    cpe:2.3:a:openstack:nova:14.0.2
  • Openstack » Nova » Version: 14.0.3
    cpe:2.3:a:openstack:nova:14.0.3
  • Openstack » Nova » Version: 14.0.4
    cpe:2.3:a:openstack:nova:14.0.4
  • Openstack » Nova » Version: 14.0.5
    cpe:2.3:a:openstack:nova:14.0.5
  • Openstack » Nova » Version: 14.0.6
    cpe:2.3:a:openstack:nova:14.0.6
  • Openstack » Nova » Version: 14.0.7
    cpe:2.3:a:openstack:nova:14.0.7
  • Openstack » Nova » Version: 14.0.8
    cpe:2.3:a:openstack:nova:14.0.8
  • Openstack » Nova » Version: 14.0.9
    cpe:2.3:a:openstack:nova:14.0.9
  • Openstack » Nova » Version: 14.1.0
    cpe:2.3:a:openstack:nova:14.1.0
  • Openstack » Nova » Version: 15.0.0
    cpe:2.3:a:openstack:nova:15.0.0
  • Openstack » Nova » Version: 15.0.1
    cpe:2.3:a:openstack:nova:15.0.1
  • Openstack » Nova » Version: 15.0.2
    cpe:2.3:a:openstack:nova:15.0.2
  • Openstack » Nova » Version: 15.0.3
    cpe:2.3:a:openstack:nova:15.0.3
  • Openstack » Nova » Version: 15.0.4
    cpe:2.3:a:openstack:nova:15.0.4
  • Openstack » Nova » Version: 15.0.5
    cpe:2.3:a:openstack:nova:15.0.5
  • Openstack » Nova » Version: 15.0.6
    cpe:2.3:a:openstack:nova:15.0.6
  • Openstack » Nova » Version: 15.0.7
    cpe:2.3:a:openstack:nova:15.0.7
  • Openstack » Nova » Version: 15.0.8
    cpe:2.3:a:openstack:nova:15.0.8
  • Openstack » Nova » Version: 15.1.0
    cpe:2.3:a:openstack:nova:15.1.0
  • Openstack » Nova » Version: 15.1.1
    cpe:2.3:a:openstack:nova:15.1.1
  • Openstack » Nova » Version: 15.1.2
    cpe:2.3:a:openstack:nova:15.1.2
  • Openstack » Nova » Version: 15.1.3
    cpe:2.3:a:openstack:nova:15.1.3
  • Openstack » Nova » Version: 15.1.4
    cpe:2.3:a:openstack:nova:15.1.4
  • Openstack » Nova » Version: 15.1.5
    cpe:2.3:a:openstack:nova:15.1.5
  • Openstack » Nova » Version: 16.0.0
    cpe:2.3:a:openstack:nova:16.0.0
  • Openstack » Nova » Version: 16.0.1
    cpe:2.3:a:openstack:nova:16.0.1
  • Openstack » Nova » Version: 16.0.2
    cpe:2.3:a:openstack:nova:16.0.2
  • Openstack » Nova » Version: 16.0.3
    cpe:2.3:a:openstack:nova:16.0.3
  • Openstack » Nova » Version: 16.0.4
    cpe:2.3:a:openstack:nova:16.0.4
  • Openstack » Nova » Version: 16.1.0
    cpe:2.3:a:openstack:nova:16.1.0
  • Openstack » Nova » Version: 16.1.1
    cpe:2.3:a:openstack:nova:16.1.1
  • Openstack » Nova » Version: 16.1.2
    cpe:2.3:a:openstack:nova:16.1.2
  • Openstack » Nova » Version: 16.1.3
    cpe:2.3:a:openstack:nova:16.1.3
  • Openstack » Nova » Version: 16.1.4
    cpe:2.3:a:openstack:nova:16.1.4
  • Openstack » Nova » Version: 16.1.5
    cpe:2.3:a:openstack:nova:16.1.5
  • Openstack » Nova » Version: 16.1.6
    cpe:2.3:a:openstack:nova:16.1.6
  • Openstack » Nova » Version: 16.1.7
    cpe:2.3:a:openstack:nova:16.1.7
  • Openstack » Nova » Version: 16.1.8
    cpe:2.3:a:openstack:nova:16.1.8
  • Openstack » Nova » Version: 17.0.0
    cpe:2.3:a:openstack:nova:17.0.0
  • Openstack » Nova » Version: 17.0.1
    cpe:2.3:a:openstack:nova:17.0.1
  • Openstack » Nova » Version: 17.0.10
    cpe:2.3:a:openstack:nova:17.0.10
  • Openstack » Nova » Version: 17.0.11
    cpe:2.3:a:openstack:nova:17.0.11
  • Openstack » Nova » Version: 17.0.12
    cpe:2.3:a:openstack:nova:17.0.12
  • Openstack » Nova » Version: 17.0.13
    cpe:2.3:a:openstack:nova:17.0.13
  • Openstack » Nova » Version: 17.0.2
    cpe:2.3:a:openstack:nova:17.0.2
  • Openstack » Nova » Version: 17.0.3
    cpe:2.3:a:openstack:nova:17.0.3
  • Openstack » Nova » Version: 17.0.4
    cpe:2.3:a:openstack:nova:17.0.4
  • Openstack » Nova » Version: 17.0.5
    cpe:2.3:a:openstack:nova:17.0.5
  • Openstack » Nova » Version: 17.0.6
    cpe:2.3:a:openstack:nova:17.0.6
  • Openstack » Nova » Version: 17.0.7
    cpe:2.3:a:openstack:nova:17.0.7
  • Openstack » Nova » Version: 17.0.8
    cpe:2.3:a:openstack:nova:17.0.8
  • Openstack » Nova » Version: 17.0.9
    cpe:2.3:a:openstack:nova:17.0.9
  • Openstack » Nova » Version: 18.0.0
    cpe:2.3:a:openstack:nova:18.0.0
  • Openstack » Nova » Version: 18.0.1
    cpe:2.3:a:openstack:nova:18.0.1
  • Openstack » Nova » Version: 18.0.2
    cpe:2.3:a:openstack:nova:18.0.2
  • Openstack » Nova » Version: 18.0.3
    cpe:2.3:a:openstack:nova:18.0.3
  • Openstack » Nova » Version: 18.1.0
    cpe:2.3:a:openstack:nova:18.1.0
  • Openstack » Nova » Version: 18.2.0
    cpe:2.3:a:openstack:nova:18.2.0
  • Openstack » Nova » Version: 18.2.1
    cpe:2.3:a:openstack:nova:18.2.1
  • Openstack » Nova » Version: 18.2.2
    cpe:2.3:a:openstack:nova:18.2.2
  • Openstack » Nova » Version: 18.2.3
    cpe:2.3:a:openstack:nova:18.2.3
  • Openstack » Nova » Version: 18.2.4
    cpe:2.3:a:openstack:nova:18.2.4
  • Openstack » Nova » Version: 19.0.0
    cpe:2.3:a:openstack:nova:19.0.0
  • Openstack » Nova » Version: 19.0.1
    cpe:2.3:a:openstack:nova:19.0.1
  • Openstack » Nova » Version: 19.0.2
    cpe:2.3:a:openstack:nova:19.0.2
  • Openstack » Nova » Version: 19.0.3
    cpe:2.3:a:openstack:nova:19.0.3
  • Openstack » Nova » Version: 19.1.0
    cpe:2.3:a:openstack:nova:19.1.0
  • Openstack » Nova » Version: 19.3.1
    cpe:2.3:a:openstack:nova:19.3.1
  • Openstack » Nova » Version: 20.0.0
    cpe:2.3:a:openstack:nova:20.0.0
  • Openstack » Nova » Version: 20.1.0
    cpe:2.3:a:openstack:nova:20.1.0
  • Openstack » Nova » Version: 20.3.1
    cpe:2.3:a:openstack:nova:20.3.1
  • Openstack » Nova » Version: 21.0.0
    cpe:2.3:a:openstack:nova:21.0.0
  • Openstack » Nova » Version: 21.2.3
    cpe:2.3:a:openstack:nova:21.2.3
  • Openstack » Nova » Version: 22.0.0
    cpe:2.3:a:openstack:nova:22.0.0
  • Openstack » Nova » Version: 22.2.3
    cpe:2.3:a:openstack:nova:22.2.3
  • Openstack » Nova » Version: 23.0.0
    cpe:2.3:a:openstack:nova:23.0.0
  • Openstack » Nova » Version: 23.0.3
    cpe:2.3:a:openstack:nova:23.0.3
  • Openstack » Nova » Version: 23.2.1
    cpe:2.3:a:openstack:nova:23.2.1
  • Openstack » Nova » Version: 23.2.2
    cpe:2.3:a:openstack:nova:23.2.2
  • Openstack » Nova » Version: 24.0.0
    cpe:2.3:a:openstack:nova:24.0.0
  • Openstack » Nova » Version: 24.1.1
    cpe:2.3:a:openstack:nova:24.1.1
  • Openstack » Nova » Version: 24.1.2
    cpe:2.3:a:openstack:nova:24.1.2
  • Openstack » Nova » Version: 25.0.0
    cpe:2.3:a:openstack:nova:25.0.0
  • Openstack » Nova » Version: 25.0.1
    cpe:2.3:a:openstack:nova:25.0.1
  • Openstack » Nova » Version: 25.0.2
    cpe:2.3:a:openstack:nova:25.0.2
  • Openstack » Nova » Version: 27.3.1
    cpe:2.3:a:openstack:nova:27.3.1
  • Openstack » Nova » Version: 27.4.0
    cpe:2.3:a:openstack:nova:27.4.0
  • Openstack » Nova » Version: 28.0.0
    cpe:2.3:a:openstack:nova:28.0.0
  • Openstack » Nova » Version: 28.1.1
    cpe:2.3:a:openstack:nova:28.1.1
  • Openstack » Nova » Version: 28.2.0
    cpe:2.3:a:openstack:nova:28.2.0
  • Openstack » Nova » Version: 29.0.0
    cpe:2.3:a:openstack:nova:29.0.0
  • Openstack » Nova » Version: 29.0.1
    cpe:2.3:a:openstack:nova:29.0.1
  • Openstack » Nova » Version: 29.0.2
    cpe:2.3:a:openstack:nova:29.0.2
  • Openstack » Nova » Version: 29.0.3
    cpe:2.3:a:openstack:nova:29.0.3
  • Openstack » Nova » Version: 29.1.0
    cpe:2.3:a:openstack:nova:29.1.0


Contact Us

Shodan ® - All rights reserved