nova@30.2.1 vulnerabilities

Cloud computing fabric controller

Direct Vulnerabilities

Known vulnerabilities in the nova package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
External Control of File Name or Path

nova is an OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, XenServer, OpenStack Ironic and PowerVM.

Affected versions of this package are vulnerable to External Control of File Name or Path via unconstrained handling of disk image formats when invoking qemu-img. An attacker can overwrite arbitrary files on the compute host with the privileges of the Nova service by crafting a malicious QCOW2 header on an ephemeral or root disk and triggering destructive behavior during instance operations such as resize.

How to fix External Control of File Name or Path?

A fix was pushed into the master branch but not yet published.

[0,)