Comment 13 for bug 1415087

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Format-guessing and file disclosure in image convert

@waldi: I couldn't find your affiliation, any company you want to be mentioned with this advisory ?

@nova-coresec: Can you check if other vulnerable image conversions exist (beside the snapshot upload) ?

Assuming this affects all cinder backend, here is impact description draft #1:

Title: Host file disclosure through qcow2 backing file
Reporter: Bastian Blank
Products: Cinder and Nova
Affects: up to 2014.1.3 and 2014.2 versions through 2014.2.2

Description:
Bastian Blank reported a vulnerability in Cinder and Nova. By creating a qcow2 image with an arbitrary backing file, an authenticated user may mislead Cinder upload-to-image action, resulting in disclosure of any file from the Cinder server. A similar vulnerability in Nova can also be used by an authenticated user to trick Nova during a snapshot upload, resulting in disclosure of any file for which the Nova process user has access to. All Cinder setups and all Nova setups with force_raw_image (which is set by default) are affected.