CVE Vulnerabilities

CVE-2023-2088

Expected Behavior Violation

Published: May 12, 2023 | Modified: Nov 04, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Weakness

A feature, API, or function does not perform according to its specification.

Affected Software

NameVendorStart VersionEnd Version
OpenstackRedhat- (including)- (including)
Red Hat OpenStack Platform 13.0 - ELSRedHatopenstack-nova-1:17.0.13-41.el7ost*
Red Hat OpenStack Platform 13.0 - ELSRedHatpython-glance-store-0:0.23.1-0.20190916165255.cc7ecc1.el7ost*
Red Hat OpenStack Platform 13.0 - ELSRedHatpython-os-brick-0:2.3.9-12.el7ost*
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSRedHatopenstack-nova-1:17.0.13-41.el7ost*
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSRedHatpython-glance-store-0:0.23.1-0.20190916165255.cc7ecc1.el7ost*
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSRedHatpython-os-brick-0:2.3.9-12.el7ost*
Red Hat OpenStack Platform 16.1RedHatopenstack-cinder-1:15.4.0-1.20230510003501.58f0e73.el8ost*
Red Hat OpenStack Platform 16.1RedHatopenstack-nova-1:20.4.1-1.20221005193232.el8ost*
Red Hat OpenStack Platform 16.1RedHatpython-glance-store-0:1.0.2-1.20220219073735.el8ost*
Red Hat OpenStack Platform 16.1RedHatpython-os-brick-0:2.10.5-1.20220112193420.634fb4a.el8ost*
Red Hat OpenStack Platform 16.2RedHatopenstack-cinder-1:15.6.1-2.20230310075425.a19c1c9.el8ost*
Red Hat OpenStack Platform 16.2RedHatopenstack-nova-1:20.6.2-2.20230308185149.el8ost*
Red Hat OpenStack Platform 16.2RedHatpython-glance-store-0:1.0.2-2.20230309124927.79e043a.el8ost*
Red Hat OpenStack Platform 16.2RedHatpython-os-brick-0:2.10.8-2.20220112064936.458bfad.el8ost*
Red Hat OpenStack Platform 16.2RedHattripleo-ansible-0:0.8.1-2.20230309004941.el8ost*
Red Hat OpenStack Platform 17.0RedHatopenstack-cinder-1:18.2.1-0.20230509200451.1776695.el9ost*
Red Hat OpenStack Platform 17.0RedHatopenstack-nova-1:23.2.2-0.20221209190754.7074ac0.el9ost*
Red Hat OpenStack Platform 17.0RedHatpython-glance-store-0:2.5.1-0.20230509140449.5f1cee6.el9ost*
Red Hat OpenStack Platform 17.0RedHatpython-os-brick-0:4.3.3-0.20220715140803.d09dc9e.el9ost*
Red Hat OpenStack Platform 17.0RedHattripleo-ansible-0:3.3.1-0.20221208161844.fa5422f.el9ost*
CinderUbuntubionic*
CinderUbuntuesm-infra/bionic*
CinderUbuntuesm-infra/focal*
CinderUbuntuesm-infra/xenial*
CinderUbuntufocal*
CinderUbuntujammy*
CinderUbuntukinetic*
CinderUbuntulunar*
CinderUbuntutrusty*
CinderUbuntuupstream*
CinderUbuntuxenial*
IronicUbuntubionic*
IronicUbuntuesm-apps/bionic*
IronicUbuntuesm-apps/focal*
IronicUbuntuesm-apps/jammy*
IronicUbuntuesm-apps/xenial*
IronicUbuntufocal*
IronicUbuntujammy*
IronicUbuntukinetic*
IronicUbuntulunar*
IronicUbuntutrusty*
IronicUbuntuxenial*
NovaUbuntubionic*
NovaUbuntudevel*
NovaUbuntuesm-infra/bionic*
NovaUbuntuesm-infra/focal*
NovaUbuntuesm-infra/xenial*
NovaUbuntufocal*
NovaUbuntujammy*
NovaUbuntukinetic*
NovaUbuntulunar*
NovaUbuntutrusty*
NovaUbuntuupstream*
NovaUbuntuxenial*
Python-glance-storeUbuntubionic*
Python-glance-storeUbuntuesm-infra/bionic*
Python-glance-storeUbuntuesm-infra/focal*
Python-glance-storeUbuntuesm-infra/xenial*
Python-glance-storeUbuntufocal*
Python-glance-storeUbuntujammy*
Python-glance-storeUbuntukinetic*
Python-glance-storeUbuntulunar*
Python-glance-storeUbuntutrusty*
Python-glance-storeUbuntuxenial*
Python-os-brickUbuntubionic*
Python-os-brickUbuntuesm-infra/bionic*
Python-os-brickUbuntuesm-infra/focal*
Python-os-brickUbuntuesm-infra/xenial*
Python-os-brickUbuntufocal*
Python-os-brickUbuntujammy*
Python-os-brickUbuntukinetic*
Python-os-brickUbuntulunar*
Python-os-brickUbuntutrusty*
Python-os-brickUbuntuxenial*

References