CVE-2015-1851

Canonical Ubuntu Linux < 2014.1.4 - Information Disclosure

Title source: rule

Description

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.

Scores

EPSS 0.0049
EPSS Percentile 65.1%

Classification

CWE
CWE-200
Status draft

Affected Products (7)

canonical/ubuntu_linux
openstack/icehouse < 2014.1.4
openstack/juno
openstack/juno
openstack/juno
openstack/kilo
pypi/cinder < 7.0.0a0PyPI

Timeline

Published Jun 25, 2015
Tracked Since Feb 18, 2026