Threat Advisory

Critical OpenStack Nova Vulnerability Threatens Cloud Security

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability in OpenStack’s Nova component, tracked as CVE-2024-40767, has been identified, posing a significant risk to cloud infrastructure globally. This flaw affects Nova versions below 27.4.1, between 28.0.0 and 28.2.1, and between 29.0.0 and 29.1.1. The vulnerability allows an authenticated user to exploit a raw format image, such as a specially crafted QCOW2 or VMDK flat image, to access sensitive data stored on cloud servers. By manipulating the image's backing file path, attackers can retrieve unauthorized content, leading to potential data breaches. The OpenStack community has swiftly released patches to mitigate the risk, urging administrators to update their systems immediately. This incident highlights the ongoing need for vigilance and proactive security measures within the tech community to protect digital infrastructure from evolving threats.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability in OpenStack’s Nova component, tracked as CVE-2024-40767, has been identified, posing a significant risk to cloud infrastructure globally. This flaw affects Nova versions below 27.4.1, between 28.0.0 and 28.2.1, and between 29.0.0 and 29.1.1. The vulnerability allows an authenticated user to exploit a raw format image, such as a specially crafted QCOW2 or VMDK flat image, to access sensitive data stored on cloud servers. By manipulating the image's backing file path, attackers can retrieve unauthorized content, leading to potential data breaches. The OpenStack community has swiftly released patches to mitigate the risk, urging administrators to update their systems immediately. This incident highlights the ongoing need for vigilance and proactive security measures within the tech community to protect digital infrastructure from evolving threats.[emaillocker id="1283"]

RECOMMENDATION:

We strongly recommend you update Nova products to below versions:

  • Patch for 2023.1/antelope
  • Patch for 2023.2/bobcat
  • Patch for 2024.1/caracal
  • Patch for 2024.2/dalmatian

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/openstack-nova-vulnerability/

https://security.openstack.org/ossa/OSSA-2024-002.html

[/emaillocker]
crossmenu