UBUNTU-CVE-2023-2088
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-2088
UBUNTU-CVE-2023-2088
Summary:
Details: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
References: https://ubuntu.com/security/CVE-2023-2088, https://ubuntu.com/security/notices/USN-6073-1, https://ubuntu.com/security/notices/USN-6073-2, https://ubuntu.com/security/notices/USN-6073-3, https://ubuntu.com/security/notices/USN-6073-4, https://ubuntu.com/security/notices/USN-6073-5, https://ubuntu.com/security/notices/USN-6073-6, https://ubuntu.com/security/notices/USN-6073-7, https://ubuntu.com/security/notices/USN-6073-8, https://ubuntu.com/security/notices/USN-6073-9, https://ubuntu.com/security/notices/USN-6241-1, https://www.cve.org/CVERecord?id=CVE-2023-2088
Affected packages
Package
Name: cinder
Purl: pkg:deb/ubuntu/cinder@2:8.1.1-0ubuntu3?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
