CVE-2023-2088 Affecting cinder package, versions <2:21.1.0-3
Threat Intelligence
EPSS
0.09% (39th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN13-CINDER-5678038
- published 11 May 2023
- disclosed 12 May 2023
Introduced: 11 May 2023
CVE-2023-2088 Open this link in a new tabHow to fix?
Upgrade Debian:13
cinder
to version 2:21.1.0-3 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream cinder
package and not the cinder
package as distributed by Debian
.
See How to fix?
for Debian:13
relevant fixed versions and status.
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
CVSS Scores
version 3.1