Exposure of Sensitive Information to an Unauthorized Actor Affecting nova package, versions [,29.2.0)
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-NOVA-7554718
- published 24 Jul 2024
- disclosed 24 Jul 2024
- credit Arnaud Morin
Introduced: 24 Jul 2024
CVE-2024-40767 Open this link in a new tabHow to fix?
Upgrade nova
to version 29.2.0 or higher.
Overview
nova is an OpenStack Nova provides a cloud computing fabric controller, supporting a wide variety of compute technologies, including: libvirt (KVM, Xen, LXC and more), Hyper-V, VMware, XenServer, OpenStack Ironic and PowerVM.
Affected versions of this package are vulnerable to Exposure of Sensitive Information to an Unauthorized Actor due to improper input validation. An attacker can access sensitive data by supplying a specially crafted image that masquerades as a different format, which then references files on the server.