Vulnerability Details CVE-2024-40767
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-40767
-
cpe:2.3:a:openstack:nova:-
-
cpe:2.3:a:openstack:nova:0.9.0
-
cpe:2.3:a:openstack:nova:12.0.0
-
cpe:2.3:a:openstack:nova:12.0.1
-
cpe:2.3:a:openstack:nova:12.0.2
-
cpe:2.3:a:openstack:nova:12.0.3
-
cpe:2.3:a:openstack:nova:12.0.4
-
cpe:2.3:a:openstack:nova:12.0.5
-
cpe:2.3:a:openstack:nova:12.0.6
-
cpe:2.3:a:openstack:nova:13.0.0
-
cpe:2.3:a:openstack:nova:13.1.0
-
cpe:2.3:a:openstack:nova:13.1.1
-
cpe:2.3:a:openstack:nova:13.1.2
-
cpe:2.3:a:openstack:nova:13.1.3
-
cpe:2.3:a:openstack:nova:13.1.4
-
cpe:2.3:a:openstack:nova:14.0.0
-
cpe:2.3:a:openstack:nova:14.0.1
-
cpe:2.3:a:openstack:nova:14.0.10
-
cpe:2.3:a:openstack:nova:14.0.2
-
cpe:2.3:a:openstack:nova:14.0.3
-
cpe:2.3:a:openstack:nova:14.0.4
-
cpe:2.3:a:openstack:nova:14.0.5
-
cpe:2.3:a:openstack:nova:14.0.6
-
cpe:2.3:a:openstack:nova:14.0.7
-
cpe:2.3:a:openstack:nova:14.0.8
-
cpe:2.3:a:openstack:nova:14.0.9
-
cpe:2.3:a:openstack:nova:14.1.0
-
cpe:2.3:a:openstack:nova:15.0.0
-
cpe:2.3:a:openstack:nova:15.0.1
-
cpe:2.3:a:openstack:nova:15.0.2
-
cpe:2.3:a:openstack:nova:15.0.3
-
cpe:2.3:a:openstack:nova:15.0.4
-
cpe:2.3:a:openstack:nova:15.0.5
-
cpe:2.3:a:openstack:nova:15.0.6
-
cpe:2.3:a:openstack:nova:15.0.7
-
cpe:2.3:a:openstack:nova:15.0.8
-
cpe:2.3:a:openstack:nova:15.1.0
-
cpe:2.3:a:openstack:nova:15.1.1
-
cpe:2.3:a:openstack:nova:15.1.2
-
cpe:2.3:a:openstack:nova:15.1.3
-
cpe:2.3:a:openstack:nova:15.1.4
-
cpe:2.3:a:openstack:nova:15.1.5
-
cpe:2.3:a:openstack:nova:16.0.0
-
cpe:2.3:a:openstack:nova:16.0.1
-
cpe:2.3:a:openstack:nova:16.0.2
-
cpe:2.3:a:openstack:nova:16.0.3
-
cpe:2.3:a:openstack:nova:16.0.4
-
cpe:2.3:a:openstack:nova:16.1.0
-
cpe:2.3:a:openstack:nova:16.1.1
-
cpe:2.3:a:openstack:nova:16.1.2
-
cpe:2.3:a:openstack:nova:16.1.3
-
cpe:2.3:a:openstack:nova:16.1.4
-
cpe:2.3:a:openstack:nova:16.1.5
-
cpe:2.3:a:openstack:nova:16.1.6
-
cpe:2.3:a:openstack:nova:16.1.7
-
cpe:2.3:a:openstack:nova:16.1.8
-
cpe:2.3:a:openstack:nova:17.0.0
-
cpe:2.3:a:openstack:nova:17.0.1
-
cpe:2.3:a:openstack:nova:17.0.10
-
cpe:2.3:a:openstack:nova:17.0.11
-
cpe:2.3:a:openstack:nova:17.0.12
-
cpe:2.3:a:openstack:nova:17.0.13
-
cpe:2.3:a:openstack:nova:17.0.2
-
cpe:2.3:a:openstack:nova:17.0.3
-
cpe:2.3:a:openstack:nova:17.0.4
-
cpe:2.3:a:openstack:nova:17.0.5
-
cpe:2.3:a:openstack:nova:17.0.6
-
cpe:2.3:a:openstack:nova:17.0.7
-
cpe:2.3:a:openstack:nova:17.0.8
-
cpe:2.3:a:openstack:nova:17.0.9
-
cpe:2.3:a:openstack:nova:18.0.0
-
cpe:2.3:a:openstack:nova:18.0.1
-
cpe:2.3:a:openstack:nova:18.0.2
-
cpe:2.3:a:openstack:nova:18.0.3
-
cpe:2.3:a:openstack:nova:18.1.0
-
cpe:2.3:a:openstack:nova:18.2.0
-
cpe:2.3:a:openstack:nova:18.2.1
-
cpe:2.3:a:openstack:nova:18.2.2
-
cpe:2.3:a:openstack:nova:18.2.3
-
cpe:2.3:a:openstack:nova:18.2.4
-
cpe:2.3:a:openstack:nova:19.0.0
-
cpe:2.3:a:openstack:nova:19.0.1
-
cpe:2.3:a:openstack:nova:19.0.2
-
cpe:2.3:a:openstack:nova:19.0.3
-
cpe:2.3:a:openstack:nova:19.1.0
-
cpe:2.3:a:openstack:nova:19.3.1
-
cpe:2.3:a:openstack:nova:20.0.0
-
cpe:2.3:a:openstack:nova:20.1.0
-
cpe:2.3:a:openstack:nova:20.3.1
-
cpe:2.3:a:openstack:nova:21.0.0
-
cpe:2.3:a:openstack:nova:21.2.3
-
cpe:2.3:a:openstack:nova:22.0.0
-
cpe:2.3:a:openstack:nova:22.2.3
-
cpe:2.3:a:openstack:nova:23.0.0
-
cpe:2.3:a:openstack:nova:23.0.3
-
cpe:2.3:a:openstack:nova:23.2.1
-
cpe:2.3:a:openstack:nova:23.2.2
-
cpe:2.3:a:openstack:nova:24.0.0
-
cpe:2.3:a:openstack:nova:24.1.1
-
cpe:2.3:a:openstack:nova:24.1.2
-
cpe:2.3:a:openstack:nova:25.0.0
-
cpe:2.3:a:openstack:nova:25.0.1
-
cpe:2.3:a:openstack:nova:25.0.2
-
cpe:2.3:a:openstack:nova:27.3.1
-
cpe:2.3:a:openstack:nova:27.4.0
-
cpe:2.3:a:openstack:nova:28.0.0
-
cpe:2.3:a:openstack:nova:28.1.1
-
cpe:2.3:a:openstack:nova:28.2.0
-
cpe:2.3:a:openstack:nova:29.0.0
-
cpe:2.3:a:openstack:nova:29.0.1
-
cpe:2.3:a:openstack:nova:29.0.2
-
cpe:2.3:a:openstack:nova:29.0.3
-
cpe:2.3:a:openstack:nova:29.1.0