Improper Input Validation Affecting nova package, versions [,27.4.0) [28.0.0,28.2.0) [29.0.0,29.1.0)
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-NOVA-7430273
- published 8 Jul 2024
- disclosed 2 Jul 2024
- credit Martin Kaesberger
Introduced: 2 Jul 2024
CVE-2024-32498 Open this link in a new tabHow to fix?
Upgrade nova
to version 27.4.0, 28.2.0, 29.1.0 or higher.
Overview
nova is an OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, XenServer, OpenStack Ironic and PowerVM.
Affected versions of this package are vulnerable to Improper Input Validation in QCOW2
image processing. An authenticated user may convince systems to return a copy of that file's contents from the server resulting in unauthorized access to potentially sensitive data and unbounded memory/CPU consumption.
Note: All Cinder deployments are affected; only Glance deployments with image conversion enabled are affected; all Nova deployments are affected.