A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
A feature, API, or function does not perform according to its specification.
Link | Tags |
---|---|
https://security.openstack.org/ossa/OSSA-2023-003.html | |
https://bugs.launchpad.net/bugs/2004555 | issue tracking |