Cinder
Vendor:
First CVE: Sep 16, 2013 · Active for 12 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
4.6
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cinder over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2013
12 years ago
Most Recent CVE
Jul 5, 2024
750 days ago
CVE Severity & Scoring
Cinder9 CVEs
33%
44%
22%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High0 (0.0%)
Unknown5 (55.6%)
User Interaction
None3 (33.3%)
Unknown5 (55.6%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None2 (22.2%)
Unknown5 (55.6%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15139HIGH A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. | Aug 27, 2018 | 7.5 | 25 | NO | NO |
CVE-2024-32498MEDIUM An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplyi | Jul 5, 2024 | 6.5 | 23 | NO | NO |
CVE-2022-47951MEDIUM An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before | Jan 26, 2023 | 5.7 | 21 | NO | NO |
CVE-2015-5162HIGH The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which | Oct 7, 2016 | 7.5 | 20 | NO | NO |
CVE-2014-3641MEDIUM The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and a | Oct 8, 2014 | 4.0 | 17 | NO | NO |
CVE-2013-4202MEDIUM The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause | Sep 16, 2013 | 4.3 | 14 | NO | NO |
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when | Oct 8, 2014 | 2.1 | 11 | NO | NO |
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from comman | Oct 8, 2014 | 2.1 | 11 | NO | NO |
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to | Sep 16, 2013 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Cinder
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 8.0.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 7.0.2 | 1 | 7.5 | 3.1% | 0 | 0 |
| 24.0.0 | 1 | 6.5 | 0.8% | 0 | 0 |
| 2014.1.1 | 1 | 4.0 | 1.9% | 0 | 0 |
| 2013.1.2 | 1 | 2.1 | 0.4% | 0 | 0 |
| 2013.1.1 | 1 | 2.1 | 0.4% | 0 | 0 |