CVE-2022-47951 - CVE House
Back to Database
Status published Unknown CVE-2022-47951

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x...

Vulnerability Description

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-47951

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cinder, glance, nova, debian linux
Vulnerable Versions:
0, 20.0.0, 24.0.0, 25.0.0, 10.0, 11.0

Timeline

Official Publish: January 26th, 2023
Last Modified: March 31st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.